2020-03-16 - QUICK POST: MALSPAM KNOWN FOR URSNIF SWITCHES TO ICEDID
- 2020-03-16-IcedID-infection-traffic.pcap.zip 891 kB (890,597 bytes)
- 2020-03-16-IcedID-malware-and-artifacts.zip 222 kB (221,997 bytes)
- This malspam campaign is known for spreading Ursnif using English and other languages. Here is a relatively recent example.
- However, today instead of Ursnif (or Gozi/IFSB), it pushed IcedID malware.
- Chain of events: malspam --> password-protected zip attachment --> extracted Word doc --> enable macros --> IcedID
- All zip archives on this site are password-protected with the standard password. If you don't know it, see the "about" page of this website.
Shown above: VirusTotal Intelligence search for the password-protected zip archives.
Shown above: Screenshot of a Word doc extracted from one of the zip archives.
Shown above: After enabling macros, I saw a scheduled task for IcedID on an infected Windows host.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.