2020-10-06 - TA551 (SHATHAK) WORD DOCS PUSH ICEDID

ASSOCIATED FILES:

NOTES:

 

IMAGES


Shown above:  Screenshot of a Word doc with macros for TA551 (new template started today).

 


Shown above:  Traffic from an infection filtered in Wireshark.

 


Shown above:  Example of installer DLL saved to the victim's host.

 


Shown above:  Example of initial IcedID EXE created by installer DLL.

 


Shown above:  PNG file with encoded data created after the initial EXE is run.

 


Shown above:  Example of IcedID EXE persistent through scheduled task.

 

Click here to return to the main page.