2018-08-15 - QUICK POST: HANCITOR INFECTION TRAFFFIC WITH ZEUS PANDA BANKER
ASSOCIATED FILES:
- 2018-08-15-Hancitor-malspam-16-email-examples.zip 77 kB (77,121 bytes)
- 2018-08-15-Hancitor-malspam-infection-traffic.pcap.zip 493 kB (492,691 bytes)
- 2018-08-15-malware-from-Hancitor-infection.zip 330 kB (330,041 bytes)
NOTES:
- Today's Hancitor malspam started with the wrong message template for HelloFax from yesterday.
- Initial emails also had bad links to download malicious Word docs, using domains from yesterday's Hancitor malspam.
- As the day progressed, I saw more Hancitor malspam with the proper message template for UPS and new URLs for the malicious Word docs.
- Zip archives are password-protected with the standard password. If you don't know it, look at the "about" page of this website.
Shown above: Today's wave started out with the wrong message text template, but it was eventually corrected.
IMAGES
Shown above: Traffic from an infection filtered in Wireshark.
Click here to return to the main page.