2017-11-06 - HANCITOR MALSPAM - SUBJECT: DELIVERY FAILED
ASSOCIATED FILES:
- Zip archive of the pcap: 2017-11-06-Hancitor-malspam-traffic.pcap.zip 477 kB (477,326 bytes)
- 2017-11-06-Hancitor-malspam-traffic.pcap (640,743 bytes)
- Zip archive of the malware: 2017-11-06-Hancitor-artifacts.zip 218 kB (217,885 bytes)
- 2017-11-06-Hancitor-document.doc (181,760 bytes)
- 2017-11-06-Zeus-Panda-Banker.exe (153,600 bytes)
- Zip archive of the emails: 2017-11-06-Hancitor-malspam-emails.txt.zip 2.5 kB (2,504 bytes)
- 2017-11-06-Hancitor-malspam-emails.txt (40,812 bytes)
- Zip archive of the write-up: 2017-11-06-Hancitor-malspam-notes.txt.zip 1.4 kB (1,385 bytes)
- 2017-11-06-Hancitor-malspam-notes.txt (2,883 bytes)
IMAGES
Shown above: Screenshot from one of the emails.
Shown above: Following a link from one of the emails.
Shown above: A document downloaded from one of the links.
Shown above: Traffic from an infection filtered in Wireshark.
Shown above: Zeus Panda Banker made persistent on the infected Windows host.
FINAL NOTES
Once again, here are the associated files:
- Zip archive of the pcap: 2017-11-06-Hancitor-malspam-traffic.pcap.zip 477 kB (477,326 bytes)
- Zip archive of the malware: 2017-11-06-Hancitor-artifacts.zip 218 kB (217,885 bytes)
- Zip archive of the emails: 2017-11-06-Hancitor-malspam-emails.txt.zip 2.5 kB (2,504 bytes)
- Zip archive of the write-up: 2017-11-06-Hancitor-malspam-notes.txt.zip 1.4 kB (1,385 bytes)
Zip archives are password-protected with the standard password. If you don't know it, look at the "about" page of this website.
Click here to return to the main page.