2020-11-20 - TA551 (SHATHAK) WORD DOCS WITH JAPANESE TEMPALTE PUSH ICEDID
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
 
ASSOCIATED FILES
- 2020-11-20-TA551-IOCs-for-IcedID.txt.zip 4.3 kB (4,329 bytes)
 - 2020-11-20-TA551-malspam-4-examples.zip 445 kB (445,176 bytes)
 - 2020-11-20-TA551-IcedID-infections-2-pcaps.zip 4.8 MB (4,801,925 bytes)
 - 2020-11-20-TA551-IcedID-malware-and-artifacts.zip 5.0 MB (5,001,191 bytes)
 
NOTES:
- During my first run, I didn't get a persistent infection, so I did a second run a few hours later.
 - I have the pcap from the second run, but I wiped the host before I retrieved the second set of malware/artifacts.
 - The images below are from that second run where I forgot to retrieve the malware/artifacts.
 
IMAGES

Shown above:  Screenshot from one of the TA551 malspam.

Shown above:  Traffic from an infection filtered in Wireshark.

Shown above:  Artifacts seen from an infection.

Shown above:  Scheduled task to keep the infection persistent.
Click here to return to the main page.
