2016-08-17 - BOLETO CAMPAIGN

NOTICE:

ASSOCIATED FILES:

  • 2016-08-17-Boleto-campaign-infection-traffic.pcap   (1,898,762 bytes)
  • 2016-08-17-Boleto-campaign-malspam.csv   (1,404 bytes)
  • 2016-08-17-Boleto-campaign-malware-and-artifacts-info.csv   (1,893 bytes)
  • 2016-08-17-Boleto-malspam-0021-UTC.eml   (1,799 bytes)
  • 2016-08-17-Boleto-malspam-0550-UTC.eml   (1,807 bytes)
  • 2016-08-17-Boleto-malspam-0552-UTC.eml   (1,826 bytes)
  • 2016-08-17-Boleto-malspam-0701-UTC.eml   (1,799 bytes)
  • 2016-08-17-Boleto-malspam-0720-UTC.eml   (1,807 bytes)
  • 2016-08-17-Boleto-malspam-0925-UTC.eml   (1,841 bytes)
  • 2016-08-17-Boleto-malspam-1506-UTC.eml   (1,800 bytes)
  • 16082016vecO7OkL3yLPICleozibKEHa861Hzh9GF.vbs   (1,088 bytes)
  • GO-GO-GADGET-PC.aes   (16 bytes)
  • GO-GO-GADGET-PC.zip   (1,079,303 bytes)
  • Ionic.Zip.Reduced.dll   (253,440 bytes)
  • aaaaaaaaaaaa.xml   (3,394 bytes)
  • burdg5bw.2su.vbs   (350 bytes)
  • dll.dll.exe   (396,480 bytes)
  • tmp3F42.tmp   (11,548 bytes)
  • tmp7C.tmp   (11,548 bytes)
  • tmpCB2C.tmpps1   (3,482 bytes)
  • ydygpwq0.k3c.vbs   (7,775 bytes)

 

EMAILS


Shown above:  Data from the spreadsheet (1 of 2).

 


Shown above:  Data from the spreadsheet (2 of 2).

 


Shown above:  Example of the emails.

 

EMAIL DETAILS

EXAMPLES OF SENDING EMAIL ADDRESSES:

 

EXAMPLES OF SUBJECT LINES:

 

DOMAINS FROM LINKS IN THE EMAILS:

 

TRAFFIC


Shown above:  Traffic from the pcap filtered in Wireshark.

 

ASSOCIATED DOMAINS:

 

Click here to return to the main page.