2022-01-06 (THURSDAY) - TA551 (SHATHAK) PUSHES ICEDID (BOKBOT)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2022-01-06-IOCs-for-TA551-IcedID.txt.zip 3.5 kB (3,517 bytes)
- 2022-01-06-TA551-IcedID-infection.pcap.zip 2.7 MB (2,691,671 bytes)
- 2022-01-06-TA551-IcedID-malware-and-artifacts.zip 1.3 MB (1,276,035 bytes)
NOTES:
- This is the second day in a row for TA551 activity.
- Today's Word docs use and English template, but they have mostly Italian file names.
IMAGES
Shown above: Screenshot of the infection traffic filtered in Wireshark.
Click here to return to the main page.