2020-03-23 - INFO_03_23.DOC PUSHES MALWARE (VALAK, MAYBE?)

ASSOCIATED FILES:

NOTES:

 

IMAGES


Shown above:  Extracting info_03_23.doc from the zip archive.

 


Shown above:  Screenshot of the Word doc.

 


Shown above:  Traffic from the infection filtered in Wireshark.

 


Shown above:  Alerts using the ETPRO ruleset from Suricata using Sguil in Security Onion.

 


Shown above:  Initial artifacts dropped after enabling macros.

 


Shown above:  Follow-up malware/artifacts.

 


Shown above:  Scheduled task to keep the infection persistent, indicating use of an Alternate Data Stream (ADS).

 


Shown above:  Windows registry updates created during this infection.

 

Click here to return to the main page.