2017-12-06 - QUICK POST: NYMAIM INFECTION FROM UK VEHICLE VIOLATION-THEMED MALSPAM
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2017-12-06-Nymaim-infection-2-pcaps.zip 1.9 MB (1,898,222 bytes)
- 2017-12-06-Nymaim-malspam-2-examples.zip 4.9 kB (4,912 bytes)
- 2017-12-06-malware-from-Nymaim-infection.zip 1.0 MB (1,031,072 bytes)
Shown above: Screenshot from the first email I saw.
Shown above: Screenshot from the second email I saw.
Shown above: Clicking on a link from the emails.
Shown above: The downloaded Word document.
Shown above: Infection traffic in Wireshark (first pcap).
Shown above: Infection traffic in Wireshark (second pcap).
Shown above: Alerts on the infection traffic from the Emerging Threats Pro (ET Pro) ruleset using Sguil on Security Onion.
Click here to return to the main page.