2018-06-19 - MALSPAM PUSHES EMOTET AND EMOTET PUSHES ICEDID

ASSOCIATED FILES:

 

NOTES:

 

EMAILS

DATE/TIME:

 

DATA FROM 36 EMAIL EXAMPLES:

 

SPOOFED SENDING ADDRESSES:

 

SUBJECT LINES:

 

ATTACHMENT NAMES FROM EMAILS WITHOUT LINKS:

 

TRAFFIC


Shown above:  Traffic from an Emotet infection filtered in Wireshark also shows IcedID traffic.

 

LINKS FROM EMAILS WITHOUT ATTACHMENTS FOR THE INITIAL WORD DOCUMENT:

 

URLS GENERATED BY WORD MACROS FOR EMOTET MALWARE BINARY:

 

EMOTET INFECTION TRAFFIC FROM MY INFECTED LAB HOST:

 

ICEDID TRAFFIC FROM MY INFECTED LAB HOST:

 

MALWARE

MALWARE RETRIEVED FROM MY INFECTED WINDOWS HOST:

 

SHA256 HASHES FOR ATTACHED WORD DOCS WITH MACROS FOR EMOTET:

 

SHA256 HASHES FOR ATTACHED PDF FILES (NOT MALICIOUS):

 


Shown above:  Malware from this infection persistent on the infected Windows host.

 

Click here to return to the main page.