2019-05-01 - MALSPAM WITH PASSWORD-PROTECTED WORD DOC PUSHES ICEDID

NOTICE:

ASSOCIATED FILES:

  • 2019-04-26-malspam-with-password-protected-Word-doc.eml   (68,500 bytes)
  • 2019-05-01-password-protected-doc-infection-traffic.pcap   (6,992,374 bytes)
  • 2019-04-26-password-protected-Word-doc-from-malspam.doc   (48,640 bytes)
  • 2019-05-01-IcedID-malware-retrieved-by-macro-from-password-protected-Word-doc.exe   (181,760 bytes)
  • 2019-05-01-Sw9JKmXqaSj.exe-from-192_243_108_248.exe   (207,872 bytes)
  • 2019-05-01-Tinx86_14.exe-from-192_243_108_248.exe   (2,787,328 bytes)
  • 2019-05-01-scheduled-task-to-keep-IcedID-persistent.txt   (3,228 bytes)
  • 2019-05-01-sin.png-from-155_138_134_133.exe   (626,688 bytes)

 

WEB TRAFFIC BLOCK LIST

Indicators are not a block list.  If you feel the need to block web traffic, I suggest the following URLs and domains (note: these are de-fanged):

 

EMAIL


Shown above:  An example of this malspam from Friday, 2019-04-26.

 


Shown above:  The attached Word document after unlocking it with the password.

 

TRAFFIC

 


Shown above:  Traffic from an infection filtered in Wireshark.

 

TRAFFIC FROM AN INFECTED WINDOWS HOST:

 

FILE HASHES

MALWARE RETRIEVED FROM MY INFECTED WINDOWS HOST:

 

Click here to return to the main page.