2018-08-16 - TWO EMOTET INFECTIONS WITH ZEUS PANDA BANKER

NOTICE:

ASSOCIATED FILES:

  • Aug 16 2018 2018-08-14-Emotet-malspam-0942-UTC.eml   (164987 bytes)
  • 2018-08-14-Emotet-malspam-1028-UTC.eml   (159686 bytes)
  • 2018-08-14-Emotet-malspam-1430-UTC.eml   (4390 bytes)
  • 2018-08-15-Emotet-malspam-0523-UTC.eml   (169307 bytes)
  • 2018-08-15-Emotet-malspam-0730-UTC.eml   (165977 bytes)
  • 2018-08-15-Emotet-malspam-1055-UTC.eml   (187631 bytes)
  • 2018-08-15-Emotet-malspam-1236-UTC.eml   (2027 bytes)
  • 2018-08-15-Emotet-malspam-1457-UTC.eml   (2862 bytes)
  • 2018-08-16-Emotet-malspam-0905-UTC.eml   (125152 bytes)
  • 2018-08-15-Emotet-infection-traffic-with-Zeus-Panda-Banker.pcap   (1,583,713 bytes)
  • 2018-08-16-Emotet-infection-traffic-with-Zeus-Panda-Banker.pcap   (4,929,206 bytes)
  • 2018-08-15-Emotet-malwre-binary.exe  (176,128 bytes)
  • 2018-08-15-Zeus-Panda-Banker-caused-by-Emotet-infection.exe  (249,344 bytes)
  • 2018-08-15-downloaded-Word-doc-with-macro-for-Emotet.doc  (166,016 bytes)
  • 2018-08-16-Emotet-malwre-binary-1-of-2.exe  (172,032 bytes)
  • 2018-08-16-Emotet-malwre-binary-2-of-2.exe  (176,128 bytes)
  • 2018-08-16-Zeus-Panda-Banker-caused-by-Emotet-infection.exe  (225,280 bytes)
  • 2018-08-16-downloaded-Word-doc-with-macro-for-Emotet.doc  (93,056 bytes)
  • 9P3018_2018_08_15.doc  (135,936 bytes)
  • IF80406_2018_08_14.doc  (119,296 bytes)
  • MCO891938097_2018_08_15.doc  (119,680 bytes)
  • Rech 44177315677.doc  (90,496 bytes)
  • Rechnung 06521887908.doc  (115,712 bytes)
  • Rechnungs-Details TOAS - 011-AT0212.doc   (122,240 bytes)

NOTES:


Shown above:  Flow chart typical Emotet malspam infections.

 

WEB TRAFFIC BLOCK LIST

Indicators are not a block list.  If you feel the need to block web traffic, I suggest the following domains and URLs:

 

DATA FROM 9 MALSPAM EXAMPLES


Shown above:  An example of Emotet malspam from Tuesday 2018-08-14.

 


Shown above:  An example of Emotet malspam from Thursday 2018-08-16.

 

DATA FROM THE EMAILS:

 


Shown above:  Malicious Word doc downloaded from link in the malspam on Wednesday 2018-08-15.

 


Shown above:  Malicious Word doc downloaded from link in the malspam on Thursday 2018-08-16.

 

TRAFFIC


Shown above:  Traffic from an infection on Wednesday 2018-08-15 filtered in Wireshark.

 


Shown above:  Traffic from an infection on Thursday 2018-08-16 filtered in Wireshark.

 

INFECTION TRAFFIC FROM WEDNESDAY 2018-08-15:

 

INFECTION TRAFFIC FROM THURSDAY 2018-08-16:

 

FILE HASHES

MALWARE FROM THE INFECTED WINDOWS HOSTS:

 

MALICIOUS WORD DOCS ATTACHED TO THE EMAILS:

 

Click here to return to the main page.