2018-10-17 - QUICK POST: HANCITOR MALSPAM
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- Email: 2018-10-17-Hancitor-malspam-1539-UTC.eml.zip 2 kB (2,105 bytes)
- 2018-10-17-Hancitor-malspam-1539-UTC.eml (5,812 bytes)
- Traffic: 2018-10-17-Hancitor-infection-traffic-AD-environment.pcap.zip 1.5 MB (1,475,878 bytes)
- 2018-10-17-Hancitor-infection-traffic-AD-environment.pcap (2,040,486 bytes)
- Malware: 2018-10-17-malware-from-Hancitor-infection.zip 289 kB (289,072 bytes)
- 2018-10-17-downloaded-Word-doc-with-macro-for-Hancitor.doc (189,952 bytes)
- 2018-10-17-Hancitor-malware-binary.exe (60,928 bytes)
- 2018-10-17-Zeus-Panda-Banker-caused-by-Hancitor.exe (160,768 bytes)
IMAGES
Shown above: Flow chart for today's Hancitor infection (same as usual).
Shown above: Screenshot of today's email example.
Shown above: Downloading a malicious Word doc from the email link.
Shown above: Traffic from an infection filtered in Wireshark.
Click here to return to the main page.