2020-05-01 - XLS MACRO --> LOADER EXE --> ICEDID (BOKBOT)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
 
ASSOCIATED FILES:
- 2020-05-01-XLS-to-Loader-to-IcedID-IOCs.txt.zip 1.6 kB (1,571 bytes)
 - 2020-05-01-XLS-to-Loader-to-IcedID-infection-traffic.pcap.zip 5.0 MB (4,985,335 bytes)
 - 2020-05-01-XLS-to-Loader-to-IcedID-malware-and-artifacts.zip 4.9 MB (4,896,947 bytes)
 
IMAGES

Shown above:  Screenshot of the XLS spreadsheet.

Shown above:  XLS macro retrieves Loader EXE.

Shown above:  Loader EXE retrieves initial IcedID EXE.

Shown above:  Pcap from an infection filtered in Wireshark.
Click here to return to the main page.
