2017-11-06 - HANCITOR MALSPAM - SUBJECT: DELIVERY FAILED

ASSOCIATED FILES:

  • 2017-11-06-Hancitor-malspam-traffic.pcap   (640,743 bytes)
  • 2017-11-06-Hancitor-document.doc   (181,760 bytes)
  • 2017-11-06-Zeus-Panda-Banker.exe   (153,600 bytes)
  • 2017-11-06-Hancitor-malspam-emails.txt   (40,812 bytes)
  • 2017-11-06-Hancitor-malspam-notes.txt   (2,883 bytes)

 

IMAGES


Shown above:  Screenshot from one of the emails.

 


Shown above:  Following a link from one of the emails.

 


Shown above:  A document downloaded from one of the links.

 


Shown above:  Traffic from an infection filtered in Wireshark.

 


Shown above:  Zeus Panda Banker made persistent on the infected Windows host.

 

FINAL NOTES

Once again, here are the associated files:

Zip archives are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.