2020-09-23 - SPAMBOT TRAFFIC FROM QAKBOT-INFECTED HOST
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
 
ASSOCIATED FILES:
- 2020-09-23-Qakbot-spambot-activity-IOCs.txt.zip 3.3 kB (3,332 bytes)
 - 2020-09-23-example-of-Qakbot-spambot-activity.pcap.zip 5.3 MB (5,316,238 bytes)
 - 2020-09-23-Qakbot-malspam-17-examples.zip 1.3 MB (1,339,203 bytes)
 - 2020-09-23-Qakbot-malspam-attachments-17-examples.zip 1.3 MB (1,254,351 bytes)
 - 2020-09-23-Qakbot-XLS-files-17-examples.zip 1.3 MB (1,254,614 bytes)
 
IMAGES

Shown above:  Traffic from an infection filtered in Wireshark.

Shown above:  Filter to find any unencrypted SMTP messages in the pcap.

Shown above:  Extracting emails from unencrypted email traffic in the pcap.
Click here to return to the main page.
