2018-04-24 - DATA DUMP (HANCITOR, TRICKBOT, NECURS BOTNET/FLAWEDAMMYY)

NOTICE:

HANCITOR WITH ZEUS PANDA BANKER:

 

TRICKBOT:

 

POSSIBLE NECURS BOTNET MALSPAM PUSHING ARS STEALER/ASPC BOT & FLAWEDAMMYY:

 

NOTES AND IMAGES FOR NECURS BOTNET WAVE:

 


Shown above:  .url file causeing SMB traffic to blumblummpg.com to retrieve a .vbs file.

 


Shown above:  Port 80 HTTP POSTs are ARS Stealer/ASPC Bot traffic.  Port 443 traffic is FlawedAmmyy.

 


Shown above:  Some alerts on the traffic from Sguil in Security Onion using Suricata and the EmergingThreats Pro (ETPRO) ruleset.

 

Click here to return to the main page.