2016-08-16 - BOLETO CAMPAIGN

NOTICE:

ASSOCIATED FILES:

  • 2016-08-16-Boleto-campaign-infection-traffic.pcap   (3,367,311 bytes)
  • 2016-08-16-Boleto-campaign-malspam.csv   (3,827 bytes)
  • 2016-08-16-Boleto-campaign-malware-and-artifacts-info.csv   (3,227 bytes)
  • 2016-08-16-Boleto-malspam-1723-UTC.eml   (1,826 bytes)
  • 2016-08-16-Boleto-malspam-1744-UTC.eml   (1,843 bytes)
  • 2016-08-16-Boleto-malspam-1748-UTC.eml   (1,834 bytes)
  • 2016-08-16-Boleto-malspam-1804-UTC.eml   (1,826 bytes)
  • 2016-08-16-Boleto-malspam-1814-UTC.eml   (1,836 bytes)
  • 2016-08-16-Boleto-malspam-1842-UTC.eml   (1,812 bytes)
  • 2016-08-16-Boleto-malspam-1934-UTC.eml   (1,791 bytes)
  • 2016-08-16-Boleto-malspam-1939-UTC.eml   (1,804 bytes)
  • 2016-08-16-Boleto-malspam-2004-UTC.eml   (1,803 bytes)
  • 2016-08-16-Boleto-malspam-2009-UTC.eml   (1,832 bytes)
  • 2016-08-16-Boleto-malspam-2016-UTC.eml   (1,811 bytes)
  • 2016-08-16-Boleto-malspam-2043-UTC.eml   (1,838 bytes)
  • 2016-08-16-Boleto-malspam-2045-UTC.eml   (1,807 bytes)
  • 2016-08-16-Boleto-malspam-2048-UTC.eml   (1,845 bytes)
  • 2016-08-16-Boleto-malspam-2057-UTC.eml   (1,807 bytes)
  • 2016-08-16-Boleto-malspam-2059-UTC.eml   (1,835 bytes)
  • 2016-08-16-Boleto-malspam-2236-UTC.eml   (1,799 bytes)
  • 2016-08-16-Boleto-malspam-2313-UTC.eml   (1,836 bytes)
  • 2016-08-16-Boleto-malspam-2331-UTC.eml   (1,828 bytes)
  • 0vwy5x5w.sxp.vbs   (337 bytes)
  • 24ec2c3h.m0r.vbs   (337 bytes)
  • 301ghajh.5rb.vbs   (334 bytes)
  • Ionic.Zip.Reduced.dll   (253,440 bytes)
  • SCOOBYDOO-PC.aes   (16 bytes)
  • SCOOBYDOO-PC.zip   (964,004 bytes)
  • SYSSCOOBYDOOPC35.xml   (3,220 bytes)
  • VENC15082016ffmud0qJIKUpZ0wTBSLZrIg8f86C7OuY.vbs   (1,088 bytes)
  • ctb4jdr2.dh1.vbs   (337 bytes)
  • dll.dll.exe   (396,480 bytes)
  • dps4f3n3.nzt.vbs   (336 bytes)
  • edoyjk0d.h1e.vbs   (333 bytes)
  • gtaak3kr.0vz.vbs   (337 bytes)
  • h4lvi4ka.cxo.vbs   (337 bytes)
  • hirsngu3.dv1.vbs   (337 bytes)
  • jorgxg12.xni.vbs   (334 bytes)
  • jve5betr.n45.vbs   (333 bytes)
  • jvqvnoqi.2sm.vbs   (337 bytes)
  • mmnzj3rr.oyz.vbs   (7,843 bytes)
  • v33fkxhy.2m3.vbs   (336 bytes)
  • zezmigbh.hxq.vbs   (336 bytes)

 

EMAILS


Shown above:  Data from the spreadsheet (1 of 2).

 


Shown above:  Data from the spreadsheet (2 of 2).

 


Shown above:  Example of the emails.

 

EMAIL DETAILS

EXAMPLES OF SENDING EMAIL ADDRESSES:

 

EXAMPLES OF SUBJECT LINES:

 

DOMAINS FROM LINKS IN THE EMAILS:

 

TRAFFIC


Shown above:  Traffic from the pcap filtered in Wireshark.

 

ASSOCIATED DOMAINS:

 

Click here to return to the main page.