2018-10-17 - QUICK POST: HANCITOR MALSPAM
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
 
ASSOCIATED FILES:
- Email: 2018-10-17-Hancitor-malspam-1539-UTC.eml.zip 2 kB (2,105 bytes)
 
- 2018-10-17-Hancitor-malspam-1539-UTC.eml (5,812 bytes)
 
- Traffic: 2018-10-17-Hancitor-infection-traffic-AD-environment.pcap.zip 1.5 MB (1,475,878 bytes)
 
- 2018-10-17-Hancitor-infection-traffic-AD-environment.pcap (2,040,486 bytes)
 
- Malware: 2018-10-17-malware-from-Hancitor-infection.zip 289 kB (289,072 bytes)
 
- 2018-10-17-downloaded-Word-doc-with-macro-for-Hancitor.doc (189,952 bytes)
 - 2018-10-17-Hancitor-malware-binary.exe (60,928 bytes)
 - 2018-10-17-Zeus-Panda-Banker-caused-by-Hancitor.exe (160,768 bytes)
 
IMAGES

Shown above:  Flow chart for today's Hancitor infection (same as usual).

Shown above:  Screenshot of today's email example.

Shown above:  Downloading a malicious Word doc from the email link.

Shown above:  Traffic from an infection filtered in Wireshark.
Click here to return to the main page.
