2016-12-01 - GOZI (ISFB) INFECTION FROM ITALIAN EMAIL

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

 

THE EMAIL


Shown above:  Screenshot of the email.

 

EMAIL HEADER INFO:

LINK FROM THE MESSAGE TEXT:

 

THE MALICIOUS ZIP ARCHIVE

ZIP ARCHIVE:

EXTRACTED .JS FILE:

 

TRAFFIC


Shown above:  Infection traffic filtered in Wireshark.

 

ASSOCIATED DOMAINS:

 

POST-INFECTION FILE HASHES

DOWNLOADED .EXE FILE:

 

Click here to return to the main page.