2020-11-20 - TA551 (SHATHAK) WORD DOCS WITH JAPANESE TEMPALTE PUSH ICEDID
ASSOCIATED FILES
NOTES:
- All zip archives on this site are password-protected with the standard password. If you don't know it, see the "about" page of this website.
- During my first run, I didn't get a persistent infection, so I did a second run a few hours later.
- I have the pcap from the second run, but I wiped the host before I retrieved the second set of malware/artifacts.
- The images below are from that second run where I forgot to retrieve the malware/artifacts.
IMAGES
Shown above: Screenshot from one of the TA551 malspam.
Shown above: Traffic from an infection filtered in Wireshark.
Shown above: Artifacts seen from an infection.
Shown above: Scheduled task to keep the infection persistent.
Click here to return to the main page.
文章来源: https://www.malware-traffic-analysis.net/2020/11/20/index.html
如有侵权请联系:admin#unsafe.sh