2020-03-16 - QUICK POST: MALSPAM KNOWN FOR URSNIF (GOZI/ISFB) SWITCHES TO ICEDID (BOKBOT)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2020-03-16-IcedID-infection-traffic.pcap.zip 891 kB (890,597 bytes)
- 2020-03-16-IcedID-malware-and-artifacts.zip 223 kB (222,525 bytes)
NOTES:
- This malspam campaign is known for spreading Ursnif using English and other languages. Here is a relatively recent example.
- However, today instead of Ursnif (or Gozi/IFSB), it pushed IcedID malware.
- Chain of events: malspam --> password-protected zip attachment --> extracted Word doc --> enable macros --> IcedID
IMAGES
Shown above: VirusTotal Intelligence search for the password-protected zip archives.
Shown above: Screenshot of a Word doc extracted from one of the zip archives.
Shown above: After enabling macros, I saw a scheduled task for IcedID on an infected Windows host.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.