2018-12-10 - QUICK POST: MALSPAM PUSHING IMMINENT MONITOR RAT
- 2018-12-10-malspam-pushing-Imminent-Monitor-RAT-1632-UTC.eml.zip 31 kB (31,205 bytes)
- 2018-12-10-Imminent-Monitor-RAT-infection.pcap.zip 14 MB (14,182,194 bytes)
- 2018-12-10-malware-from-Imminent-Monitor-RAT-infection.zip 1.1 MB (1,146,555 bytes)
- Zip archives are password-protected with the standard password. If you don't know it, look at the "about" page of this website.
Shown above: Screenshot of the email and attached Word document.
Shown above: The macro to retrieve malware is pretty straight-forward in this case.
Shown above: Infection traffic filtered in Wireshark, and the associated open directory hosting malware.
Shown above: Malware persistent on the infected Windows host.
Click here to return to the main page.