2023-02-07 (TUESDAY) - ONENOTE FILE PUSHES UNIDENTIFIED MALWARE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
REFERENCE:
- I originally thought this was Matanbuchus, but it appears to be a new malware family.
- Initial tweet: https://twitter.com/Unit42_Intel/status/1623349272061136900
ASSOCIATED FILES:
- 2023-02-07-IOCs-for-unidentified-malware.txt.zip 1.9 kB (1,874 bytes)
- 2023-02-07-malspam-for-unidentified-malware-1158-UTC.eml.zip 104.3 kB (104,309 bytes)
- 2023-02-07-artifacts-from-unidentified-malware.zip 2.1 MB (2,145,107 bytes)
- 2023-02-07-traffic-from-unidentified-malware-infection.pcap.zip 20.8 MB (20,824,259 bytes)
IMAGES UPDATED FROM THE INITIAL TWEET
Shown above: Updated flowchart (unidentified malware instead of probable Matanbuchus).
Shown above: Updated email image (removed references to Matanbuchus).
Shown above: Updated forensic image (removed references to Matanbuchus).
Shown above: Updated Wireshark image (removed references to Matanbuchus).
Click here to return to the main page.