2021-06-02 (WEDNESDAY) - TA551 (SHATHAK) WORD DOCS --> ICEDID (BOKBOT) --> BACKCONNECT TRAFFIC & ANUBIS VNC

NOTICE:

NOTES:

ASSOCIATED FILES:

 

IMAGES


Shown above:  Screenshot of the Word document that I used to generate an infection.

 


Shown above:  Traffic from the infection filtered in Wireshark.

 


Shown above:  Screenshot from the decoded VNC traffic.

 

Click here to return to the main page.