2021-04-28 (WEDNESDAY) - TA551 (SHATHAK) PUSHES URSNIF (GOZI/ISFB)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2021-04-28-TA551-Ursnif-IOCs.txt.zip 1.3 kB (1,274 bytes)
- 2021-04-28-TA551-Ursnif-infection-traffic.pcap.zip 862 kB (862,434 bytes)
- 2021-04-28-TA551-Ursnif-malware.zip 446 kB (446,257 bytes)
IMAGES
Shown above: Word doc extracted from password-protected zip archive.
Shown above: Artifact seen after enabling macros on the Word doc.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.