本帖最后由 YorkWaugh 于 2020-3-21 11:03 编辑
下载地址: ASSOCIATED FILES: 2020-03-20-IcedID-IOCs.txt.zip 2.0 kB (1,969 bytes) 2020-03-20-IcedID-traffic.pcap.zip 3.3 MB (3,308,199 bytes) 2020-03-20-IcedID-malware-and-artifacts.zip 1.7 MB (1,656,321 bytes) NOTES: - Please read 2020-03-20-IcedID-IOCs.txt for a bit of background and current details on today's infection.
IMAGES
Shown above: Screenshot of the Word doc.

Shown above: Traffic from an infection filtered in Wireshark.

Shown above: Initial artifacts seen for a successful infection (I had to use MSHTA.EXE saved here as "microsoft.com" for this to work).

Shown above: Follow-up artifacts seen after a successful infection.

Shown above: Scheduled task to keep IcedID persistent on my infected lab host.
|