2021-03-17 - TA551 (SHATHAK) ITALIAN TEMPLATE WORD DOCS PUSH URSNIF (GOZI/ISFB)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2021-03-17-TA551-IOCs-for-Ursnif.txt.zip 4.4 kB (4,406 bytes)
- 2021-03-17-TA551-malspam-2-examples.zip 178 kB (178,053 bytes)
- 2021-03-17-TA551-Ursnif-1st-run-standalone-host.pcap.zip 10.2 MB (10,192,137 bytes)
- 2021-03-17-TA551-Ursnif-2nd-run-AD-environment.pcap.zip 15.9 MB (15,928,126 bytes)
- 2021-03-17-TA551-Ursnif-malware-and-artifacts.zip 14.6 MB (14,649,492 bytes)
IMAGES
Shown above: Italian malspam from the TA551 campaign.
Shown above: Italian template for the Word document.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.