2022-08-31 (WEDNESDAY) - ICEDID (BOKBOT) WITH COBALT STRIKE

NOTES:

ASSOCIATED FILES:

 

IMAGES


Shown above:  Traffic from the infection filtered in Wireshark, part 1 of 2.

 


Shown above:  Traffic from the infection filtered in Wireshark, part 2 of 2.

 

INDICATORS

INFECTION TRAFFIC:

HTTP TRAFFIC FOR GZIP BINARY:

ICEDID C2:

COBALT STRIKE C2:

MALWARE AND ARTIFACTS:

PASSWORD PROTECTED ZIP AND EXTRACTED ISO:

CONTENTS OF ISO IMAGE:

FILES SEEN FOR THIS INFECTION:

 

Click here to return to the main page.