2017-10-23 - BANLOAD INFECTION

NOTICE:

ASSOCIATED FILES:

  • 2017-10-23-Banload-infection-traffic.saz   (12,690,084 bytes)
  • 2017-10-23-Banload-infection-traffic.pcap   (12,729,380 bytes)
  • 2017-10-23-Brazil-malspam-1513-UTC.txt   (2,194 bytes)
  • ORCAMEN00017ODB23102017414478005410000048705-1st-run.zip   (1,263,870 bytes)
  • ORCAMEN00017ODB23102017414478005410000048705-2nd-run.zip   (1,189,284 bytes)
  • log.txt   (96 bytes)
  • ta21352362.668   (11,494,246 bytes)

 

EMAIL


Shown above:  Screenshot from the email.

 

EMAIL INFO:

 

TRAFFIC


Shown above:  Infection traffic filtered in Wireshark.

 


Shown above:  Infection traffic filtered in Fiddler.

 

URLS FROM THE INFECTION TRAFFIC - 1ST DOWNLOADED FILE:

 

POST-INFECTION TRAFFIC FROM THE 2ND DOWNLOADED FILE:

 

MALWARE

DOWNLOADED MALWARE:

 

POST-INFECTION MALWARE:

 

IMAGES


Shown above:  Clicking on one of the email links.

 


Shown above:  1st downloaded file.

 


Shown above:  2nd downloaded file an hour or so later from the same email links.

 


Shown above:  Post-infection artifacts (some items deleted after the initial infection).

 

Click here to return to the main page.