2021-06-02 (WEDNESDAY) - TA551 (SHATHAK) WORD DOCS --> ICEDID (BOKBOT) --> BACKCONNECT TRAFFIC & ANUBIS VNC
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
NOTES:
- For more on Backconnect, see: https://www.netresec.com/?page=Blog&month=2022-10&post=IcedID-BackConnect-Protocol
- For more on Anubis VNC, see: https://blog.nviso.eu/2023/03/20/icedids-vnc-backdoors-dark-cat-anubis-keyhole/
ASSOCIATED FILES:
- 2021-06-02-IOCs-for-TA551-IcedID-with-BackConnect-and-Anubis-VNC.txt.zip 4.5 kB (4,466 bytes)
- 2021-06-02-TA551-Word-docs-14-examples.zip 524 kB (524,100 bytes)
- 2021-06-02-TA551-HTA-and-DLL-files.zip 1.8 MB (1,804,440 bytes)
- 2021-06-02-TA551-IcedID-infection-traffic-with-BackConnect-and-Anubis-VNC.pcap.zip 3.4 MB (3,442,391 bytes)
- 2021-06-02-malware-and-artifacts-from-TA551-IcedID-infection.zip 1.6 MB (1,604,871 bytes)
IMAGES
Shown above: Screenshot of the Word document that I used to generate an infection.
Shown above: Traffic from the infection filtered in Wireshark.
Shown above: Screenshot from the decoded VNC traffic.
Click here to return to the main page.