2021-09-20 (MONDAY) - SQUIRRELWAFFLE LOADER WITH COBALT STRIKE

ASSOCIATED FILES:

 

NOTES:

 

IMAGES


Shown above:  Screenshot of tweet from @ffforward.

 


Shown above:  Screenshot of tweet from @Unit42_Intel.

 


Shown above:  Flow chart from the @Unit42_Intel tweet.

 


Shown above:  Using link from @ffforward's tweet to download the initial zip archive.

 


Shown above:  Downloaded zip archive and extracted Excel file.

 


Shown above:  Traffic from the infection filtered in Wireshark.

 

Click here to return to the main page.