2020-03-30 - INVOICE-THEMED MALSPAM PUSHES KPOT STEALER
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2020-03-30-Kpot-IOCs.txt.zip 2 kB (1,999 bytes)
- 2020-03-30-Kpot-malspam-10-examples.zip 25.5 kB (25,486 bytes)
- 2020-03-30-Kpot-infection-traffic.pcap.zip 819 kB (819,378 bytes)
- 2020-03-30-Kpot-malware-and-artifacts.zip 785 kB (785,803 bytes)
IMAGES
Shown above: Screenshot of malspam pushing Kpot.
Shown above: Web page that came up during the download.
Shown above: Screenshot fo the downloaded Word document.
Shown above: Infection traffic filtered in Wireshark.
Shown above: Artifacts seen on an infected Windows host.
Click here to return to the main page.