2020-03-23 - POLISH MALSPAM WITH XLS ATTACHMENT PUSHES URSNIF (GOZI/IFSB/DREAMBOT)

ASSOCIATED FILES:

NOTES:

 

IMAGES


Shown above:  Screenshot of the malspam.

 


Shown above:  Screenshot of the attached XLS spreadsheet.

 


Shown above:  Traffic from an infected Windows host.

 


Shown above:  DLL file retrieved after enabling the Word macro.

 

Click here to return to the main page.