article thumbnail

Early 2017 Hancitor Malspam Campaign - Infection and Victim Analysis.

ProtectWise

Amazon notifications, ADP notifications, and recently USPS notifications. This process has been rather successful at evading web-filter and firewall blacklists that only know the first domain as malicious. The process starts by delivering a variety of malicious emails to a list of target email addresses.