2019-10-09 - DOCUSIGN-THEMED HANCITOR MALSPAM AND INFECTION TAFFIC
- 2019-10-09-Hancitor-IOCs.txt.zip 2.0 kB (1,965 bytes)
- 2019-10-09-Hancitor-malspam-10-examples.zip 19.5 kB (19,521 bytes)
- 2019-10-09-Hancitor-infection-traffic.pcap.zip 1.2 MB (1,175,436 bytes)
- 2019-10-09-malware-and-artifacts-from-Hancitor-infection.zip 2.9 MB (2,862,375 bytes)
- Indicators of Compromise (IOCs) are also posted at: https://pastebin.com/XXANB1uP
- Zip archives are password-protected with the standard password. If you don't know it, see the "about" page of this website.
Shown above: Screenshot of today's Hancitor malspam.
Shown above: Link from the malspam sends a zip archive that contains the Word doc.
Shown above: Word doc has macros to generate a Hancitor infection.
Shown above: Traffic from an infection filtered in Wireshark.
Click here to return to the main page.