2021-07-02 (FRIDAY) - ASTAROTH/GUILDMA FROM BRAZIL MALSPAM
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2021-07-02-Astaroth-Guildma-notes.txt.zip 2.1 kB (2,069 bytes)
- 2021-07-02-Astaroth-Guildma-malspam-2-examples.zip 4.7 kB (4,721 bytes)
- 2021-07-02-Astaroth-Guildma-malware-and-artifacts.zip 3.2 MB (3,226,269 bytes)
- 2021-07-02-Astaroth-Guildma-infection-traffic.pcap.zip 5.8 MB (5,842,354 bytes)
Shown above: Screenshot from one of the emails.
Shown above: Downloading malicious zip archive from the email link.
Shown above: Extracted Windows shortcut from the downloaded zip archive.
Shown above: Some of the traffic seen during this infection filtered in Wireshark.
Shown above: Artifact from the infected Windows host.
Shown above: Another artifact from the infected Windows host.
Shown above: More artifacts and some malware found on the infected Windows host.
Shown above: Shortcut in the Windows Startup menu folder to keep the infection persistent.
Click here to return to the main page.