2020-03-16 - MORE HANCITOR MALSPAM USING COVID-19/CORONAVIRUS THEME
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2020-03-16-Hancitor-IOCs.txt.zip 1.5 kB (1,498 bytes)
- 2020-03-16-Hancitor-malspam-example.eml.zip 2.6 kB (2,616 bytes)
- 2020-03-16-Hancitor-infection-traffic-2-pcaps.zip 1.8 MB (1,819,524 bytes)
- 2020-03-16-Hancitor-malware-and-artifacts.zip 4.9 MB (4,903,666 bytes)
NOTES:
- This is a continuation of Hancitor activity reported last week on Wednesday 2020-03-11 (link)
IMAGES
Shown above: Screenshot of today's Hancitor malspam.
Shown above: Downloading a zip archive from link in the malspam.
Shown above: VBS file inside of the downloaded zip archive.
Shown above: Traffic from an infection filtered in Wireshark.
Click here to return to the main page.