2020-03-20 - ICEDID FROM INFO_03_20.DOC

ASSOCIATED FILES:

NOTES:

 

IMAGES


Shown above:  Screenshot of the Word doc.

 


Shown above:  Traffic from an infection filtered in Wireshark.

 


Shown above:  Initial artifacts seen for a successful infection (I had to use MSHTA.EXE saved here as "microsoft.com" for this to work).

 


Shown above:  Follow-up artifacts seen after a successful infection.

 


Shown above:  Scheduled task to keep IcedID persistent on my infected lab host.

 

Click here to return to the main page.