2020-02-24 - URSNIF (GOZI/ISFB) INFECTION FROM ITALIAN XLS SPREADSHEET WITH MACROS

NOTICE:

ASSOCIATED FILES:

  • 2020-02-24-IOCs-from-Ursnif-infection.txt   (2,704 bytes)
  • 2020-02-24-image-of-Fiddler-capture-from-Ursnif-infection.jpg   (3,598,945 bytes)
  • 2020-02-24-Ursnif-infection-from-Italian-XLS-macro.pcap   (2,243,962 bytes)
  • 2020-02-24-Italian-Excel-spreadsheet-with-macro-for-Emotet.bin   (71,680 bytes)
  • 2020-02-24-Ursnif-DLL-retrieved-by-Word-macro-1-of-3.bin   (249,344 bytes)
  • 2020-02-24-Ursnif-DLL-retrieved-by-Word-macro-2-of-3.bin   (249,344 bytes)
  • 2020-02-24-Ursnif-DLL-retrieved-by-Word-macro-3-of-3.bin   (249,344 bytes)
  • 2020-02-24-registry-update-for-Ursnif.txt   (10,865,862 bytes)

 

IMAGES


Shown above:  Traffic from the infection filtered in Wireshark.

 


Shown above:  Traffic from the same infection shown in a Fiddler capture.

 

Click here to return to the main page.