2019-07-02 - QUICK POST: HANCITOR INFECTION WITH COBALT STRIKE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2019-07-02-Hancitor-malspam-example.eml.zip 2.3 kB (2,300 bytes)
- 2019-07-02-Hancitor-infection-traffic.pcap.zip 495 kB (494,788 bytes)
- 2019-07-02-Hancitor-malware-and-artifacts.zip 364 kB (364,470 bytes)
NOTES:
- Since Monday 2019-07-01, Hancitor infections have included Cobalt Strike activity as noted by @James_inthe_box, @VK_Intel, and others (Twitter link).
- My Hancitor infection from today also shows signs of Cobalt Strike activity.
Click here to return to the main page.