2019-10-09 - DOCUSIGN-THEMED HANCITOR MALSPAM AND INFECTION TAFFIC
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2019-10-09-Hancitor-IOCs.txt.zip 2.0 kB (1,965 bytes)
- 2019-10-09-Hancitor-malspam-10-examples.zip 20.5 kB (20,529 bytes)
- 2019-10-09-Hancitor-infection-traffic.pcap.zip 1.2 MB (1,175,436 bytes)
- 2019-10-09-malware-and-artifacts-from-Hancitor-infection.zip 2.9 MB (2,863,301 bytes)
IMAGES
Shown above: Screenshot of today's Hancitor malspam.
Shown above: Link from the malspam sends a zip archive that contains the Word doc.
Shown above: Word doc has macros to generate a Hancitor infection.
Shown above: Traffic from an infection filtered in Wireshark.
Click here to return to the main page.