2021-05-24 (MONDAY) - TA551 (SHATHAK) WORD DOCS --> ICEDID (BOKBOT) --> BACKCONNECT TRAFFIC & ANUBIS VNC
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
NOTES:
- For more on Backconnect, see: https://www.netresec.com/?page=Blog&month=2022-10&post=IcedID-BackConnect-Protocol
- For more on Anubis VNC, see: https://blog.nviso.eu/2023/03/20/icedids-vnc-backdoors-dark-cat-anubis-keyhole/
ASSOCIATED FILES:
- 2021-05-24-IOCs-for-TA551-IcedID-with-BackConnect-and-Anubis-VNC.txt.zip 3.7 kB (3,686 bytes)
- 2021-05-24-TA551-malspam-1418-UTC.eml.zip 79.2 kB (79,249 bytes)
- 2021-05-24-TA551-IcedID-malware-and-artifacts.zip 1.4 MB (1,428,609 bytes)
- 2021-05-24-TA551-IcedID-infection-with-BackConnect-and-Anubis-VNC.pcap.zip 3.9 MB (3,873,567 bytes)
IMAGES
Shown above: Traffic from an infection filtered in Wireshark.
Shown above: Screenshot of decoded video from the VNC traffic.
Click here to return to the main page.