2018-08-14 - QUICK POST: HANCITOR INFECTION WITH ZEUS PANDA BANKER
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2018-08-14-Hancitor-malspam-1750-UTC.eml.zip 2.1 kB (2,062 bytes)
- 2018-08-14-Hancitor-infection-with-Zeus-Panda-Banker.pcap.zip 804.3 kB (804,362 bytes)
- 2018-08-14-malware-from-Hancitor-infection.zip 341.5 kB (341,499 bytes)
NOTES:
- Saw some issues with Zeus Panda Banker from Hancitor infections in my lab this week.
- Not as much Zeus Panda Banker traffic, and several DNS queries from the infected host showed "No such name".
- Otherwise, it's pretty much business as usual for Hancitor malspam.
IMAGES
Shown above: Flow chart for this infection traffic.
Shown above: Traffic from an infection filtered in Wireshark from today (2018-08-14).
Shown above: Traffic from the same infection about 2 & 1/2 hours later.
Click here to return to the main page.