2018-12-10 - QUICK POST: MALSPAM PUSHING IMMINENT MONITOR RAT
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2018-12-10-malspam-pushing-Imminent-Monitor-RAT-1632-UTC.eml.zip 31 kB (31,205 bytes)
- 2018-12-10-Imminent-Monitor-RAT-infection.pcap.zip 14 MB (14,182,194 bytes)
- 2018-12-10-malware-from-Imminent-Monitor-RAT-infection.zip 1.1 MB (1,147,123 bytes)
Shown above: Screenshot of the email and attached Word document.
Shown above: The macro to retrieve malware is pretty straight-forward in this case.
Shown above: Infection traffic filtered in Wireshark, and the associated open directory hosting malware.
Shown above: Malware persistent on the infected Windows host.
Click here to return to the main page.