2021-03-17 - TA551 (SHATHAK) ITALIAN TEMPLATE WORD DOCS PUSH URSNIF (GOZI/ISFB)
ASSOCIATED FILES:
- 2021-03-17-TA551-IOCs-for-Ursnif.txt.zip 4.4 kB (4,406 bytes)
- 2021-03-17-TA551-malspam-2-examples.zip 178 kB (177,709 bytes)
- 2021-03-17-TA551-Ursnif-1st-run-standalone-host.pcap.zip 10.2 MB (10,192,137 bytes)
- 2021-03-17-TA551-Ursnif-2nd-run-AD-environment.pcap.zip 15.9 MB (15,928,126 bytes)
- 2021-03-17-TA551-Ursnif-malware-and-artifacts.zip 14.6 MB (14,643,384 bytes)
NOTES:
IMAGES
Shown above: Italian malspam from the TA551 campaign.
Shown above: Italian template for the Word document.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.