2017-02-23 - HANCITOR MALSPAM

ASSOCIATED FILES:

  • 2017-02-23-Hancitor-malspam-traffic.pcap   (14,779,267 bytes)
  • 2017-02-22-Hancitor-malspam-1550-UTC.eml   (4,863 bytes)
  • 2017-02-22-Hancitor-malspam-1847-UTC.eml   (4,932 bytes)
  • 2017-02-23-Hancitor-malspam-1726-UTC.eml   (3,933 bytes)
  • 2017-02-23-Hancitor-malspam-1902-UTC.eml   (3,985 bytes)
  • 2017-02-23-Hancitor-malspam-1907-UTC.eml   (3,979 bytes)
  • BN87E4.tmp.exe   (257,536 bytes)
  • eFax_Harryrobershard.doc   (179,200 bytes)

NOTES:

 

EMAIL

DESCRIPTION:


Shown above:  Flow chart for today's traffic (Thursday 2017-02-23).

 


Shown above:  Screenshot from one of the emails from yesterday (Wednesday 2017-02-22).

 


Shown above:  Screenshot from another one of the emails from yesterday (Wednesday 2017-02-22).

 


Shown above:  Screenshot from one of the emails today (Thursday 2017-01-23).

 


Shown above:  Malicoius Word document (Hancitor) seen today (2017-01-23).

 

TRAFFIC


Shown above:  Traffic from the infection today (Thursday 2017-02-23) filtered in Wireshark.

 

ASSOCIATED DOMAINS AND URLS FROM THURSDAY 2017-02-23 INFECTION:

NOTE:  I was unable to grab any Word documents from the emails yesterday (2017-02-22), so I don't have any traffic for that day.

 

FILE HASHES

HANCITOR MALDOC:

DELOADER (ZLOADER):

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.