2017-02-27 - HANCITOR MALSPAM

ASSOCIATED FILES:

  • 2017-02-27-Hancitor-malspam-traffic.pcap   (15,101,064 bytes)
  • 2017-02-27-Hancitor-malspam-1551-UTC.eml   (1,634 bytes)
  • 2017-02-27-Hancitor-malspam-1557-UTC.eml   (1,656 bytes)
  • 2017-02-27-Hancitor-malspam-1617-UTC.eml   (1,686 bytes)
  • 2017-02-27-Hancitor-malspam-1636-UTC.eml   (1,635 bytes)
  • 2017-02-27-Hancitor-malspam-1952-UTC.eml   (1,596 bytes)
  • 2017-02-27-Hancitor-malspam-2019-UTC.eml   (1,620 bytes)
  • ADP_Invoice_fred.jaison.doc   (176,640 bytes)
  • BN4B90.tmp.exe   (263,680 bytes)

NOTES:

 


Shown above:  Flow chart for today's traffic.

 

EMAIL

DESCRIPTION:

 

EMAIL HEADERS:

 


Shown above:  Screenshot from one of the emails.

 


Shown above:  Malicious Word document (Hancitor).

 

TRAFFIC


Shown above:  Traffic from the infection filtered in Wireshark.

 

ASSOCIATED DOMAINS AND URLS:

 

FILE HASHES

HANCITOR MALDOC:

DELOADER (ZLOADER):

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.