2021-04-29 (THURSDAY) - TA551 (SHATHAK) PUSHES ICEDID (BOKBOT)

NOTICE:

ASSOCIATED FILES:

 

IMAGES


Shown above:  Word doc extracted from password-protected zip archive.

 


Shown above:  Artifacts seen after enabling macros on the Word doc.

 


Shown above:  Traffic from the infection filtered in Wireshark.

 


Shown above:  Scheduled task to keep IcedID malware persistent on the infected Windows host.

 

Click here to return to the main page.