2018-07-16 - QUICK POST: HANCITOR INFECTION WITH AZORULT AND ZEUS PANDA BANKER
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2018-07-16-Hancitor-malspam-32-examples.txt.zip 8.7 kB (8,687 bytes)
- 2018-07-16-Hancitor-infection-with-AZORult-and-Zeus-Panda-Banker.pcap.zip 4.3 MB (4,333,698 bytes)
- 2018-07-16-files-from-host-infected-with-Hancitor.zip 2.6 MB (2,595,267 bytes)
NOTES:
- New traffic noted during today's Hancitor infection...
- Thanks to @mesa_matt for quickly identifying this as AZORult-style traffic (link to his tweet).
- Unfortunately, I was unable to find an AZORult binary on my infected lab host.
IMAGES
Shown above: Infection traffic filtered in Wirehshark.
Shown above: This popped up (and quickly dissappeared) in the user's AppData\Local\Temp directory.
Click here to return to the main page.