2021-09-02 (THURSDAY) - HANCITOR (CHANITOR/MAN1/MOSKALVZAPOE/TA511) WITH COBALT STRIKE (BEACON)

NOTICE:

ASSOCIATED FILES:

 


Shown above:  Screenshot from a Hancitor email on Thursday 2021-09-02.

 


Shown above:  Clicking the Google Feedproxy link redirects to another malicious link that provides a Word document.

 


Shown above:  The browser redirects to DocuSign site after the Word document is presented for Download.

 


Shown above:  Screenshot of the downloaded Word document.

 


Shown above:  Enabling macros causes another Word document to briefly pop up named glib.doc.

 


Shown above:  Location of glib.doc and Hancitor DLL.

 


Shown above:  Traffic from the infection filtered in Wireshark.

 

Click here to return to the main page.