2021-03-12 - TA551 (SHATHAK) ITALIAN TEMPLATE WORD DOCS PUSH URSNIF (GOZI/ISFB)
ASSOCIATED FILES:
- 2021-03-12-TA551-IOCs-for-Ursnif.txt.zip 3.2 kB (3,205 bytes)
- 2021-03-12-TA551-Ursnif-docs-and-DLLs.zip 2.7 MB (2,662,017 bytes)
- 2021-03-12-TA551-Ursnif-infection-traffic.pcap.zip 2.3 MB (2,254,542 bytes)
NOTES:
- Originally from tweet by @JAMESWT_MHT at: https://twitter.com/JAMESWT_MHT/status/1370323101637087232
- All zip archives on this site are password-protected. If you don't know the password, see the "about" page of this website.
IMAGES
Shown above: Screenshot from one of the Word docs.
Shown above: Error after I enabled macros.
Shown above: Macro code and deobfuscated variable data.
Shown above: Traffic from one of the installer DLLs I manually downloaded.
Click here to return to the main page.