2016-08-13 - BOLETO MALSPAM

ASSOCIATED FILES:

  • 2016-08-13-boleto-malspam-traffic.pcap   (1,490,007 bytes)
  • 2016-08-13-boleto-malspam-data.csv   (3,268 bytes)
  • 2016-08-11-2002-UTC-boleto-malspam.eml   (1,826 bytes)
  • 2016-08-11-2021-UTC-boleto-malspam.eml   (1,839 bytes)
  • 2016-08-11-2043-UTC-boleto-malspam.eml   (1,772 bytes)
  • 2016-08-11-2056-UTC-boleto-malspam.eml   (1,807 bytes)
  • 2016-08-11-2106-UTC-boleto-malspam.eml   (1,855 bytes)
  • 2016-08-11-2120a-UTC-boleto-malspam.eml   (1,811 bytes)
  • 2016-08-11-2120b-UTC-boleto-malspam.eml   (1,795 bytes)
  • 2016-08-11-2123-UTC-boleto-malspam.eml   (1,803 bytes)
  • 2016-08-11-2133-UTC-boleto-malspam.eml   (1,830 bytes)
  • 2016-08-11-2134-UTC-boleto-malspam.eml   (1,826 bytes)
  • 2016-08-11-2139-UTC-boleto-malspam.eml   (1,799 bytes)
  • 2016-08-11-2206-UTC-boleto-malspam.eml   (1,807 bytes)
  • 2016-08-11-2213-UTC-boleto-malspam.eml   (1,834 bytes)
  • 2016-08-11-2238-UTC-boleto-malspam.eml   (1,811 bytes)
  • 2016-08-11-2245-UTC-boleto-malspam.eml   (1,815 bytes)
  • 2016-08-11-2325-UTC-boleto-malspam.eml   (3,659 bytes)
  • 2016-08-11-2350-UTC-boleto-malspam.eml   (1,843 bytes)
  • VCTO11082016pTCy2RTDtr0dUIc0Cqetctg0GSj0Tntc.vbs   (1,092 bytes)

NOTES:

 

EMAIL


Shown above:  Data from the spreadsheet (1 of 2).

 


Shown above:  Data from the spreadsheet (2 of 2).

 

TRAFFIC


Shown above:  Traffic from the pcap filtered in Wireshark.

 

ASSOCIATED DOMAINSDOMAINS:

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.