Shown above: Screenshot of a Word doc with macros for TA551 (new template started today).
Shown above: Traffic from an infection filtered in Wireshark.
Shown above: Example of installer DLL saved to the victim's host.
Shown above: Example of initial IcedID EXE created by installer DLL.
Shown above: PNG file with encoded data created after the initial EXE is run.
Shown above: Example of IcedID EXE persistent through scheduled task.
Click here to return to the main page.