2020-02-24 - URSNIF (GOZI/ISFB) INFECTION FROM ITALIAN XLS SPREADSHEET WITH MACROS
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2020-02-24-IOCs-from-Ursnif-infection.zip 3.4 MB (3,431,058 bytes)
- 2020-02-24-IOCs-from-Ursnif-infection.txt (2,704 bytes)
- 2020-02-24-image-of-Fiddler-capture-from-Ursnif-infection.jpg (3,598,945 bytes)
- 2020-02-24-Ursnif-infection-from-Italian-XLS-macro.pcap.zip 1.9 MB (1,887,205 bytes)
- 2020-02-24-Ursnif-infection-from-Italian-XLS-macro.pcap (2,243,962 bytes)
- 2020-02-24-malware-and-artifacts-from-Ursnif-infection.zip 2.8 MB (2,770,482 bytes)
- 2020-02-24-Italian-Excel-spreadsheet-with-macro-for-Emotet.bin (71,680 bytes)
- 2020-02-24-Ursnif-DLL-retrieved-by-Word-macro-1-of-3.bin (249,344 bytes)
- 2020-02-24-Ursnif-DLL-retrieved-by-Word-macro-2-of-3.bin (249,344 bytes)
- 2020-02-24-Ursnif-DLL-retrieved-by-Word-macro-3-of-3.bin (249,344 bytes)
- 2020-02-24-registry-update-for-Ursnif.txt (10,865,862 bytes)
IMAGES
Shown above: Traffic from the infection filtered in Wireshark.
Shown above: Traffic from the same infection shown in a Fiddler capture.
Click here to return to the main page.