2021-04-28 (WEDNESDAY) - TA551 (SHATHAK) PUSHES URSNIF (GOZI/ISFB)

ASSOCIATED FILES:

NOTES:

 

IMAGES


Shown above:  Word doc extracted from password-protected zip archive.

 


Shown above:  Artifact seen after enabling macros on the Word doc.

 


Shown above:  Traffic from the infection filtered in Wireshark.

 

Click here to return to the main page.