2021-05-14 (FRIDAY) - EMAIL ATTACHMENT FROM 10 DAYS PRIOR STILL PUSHING URSNIF (GOZI/ISFB)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2021-05-14-Ursnif-traffic-and-malware-and-IOCs.zip 1.0 MB (1,043,039 bytes)
- 2021-05-03-malspam-pushing-Ursnif.eml (134,798 bytes)
- 2021-05-14-IOCs-for-Ursnif-infection.txt (3,786 bytes)
- 2021-05-14-Ursnif-infection-traffic.pcap (821,237 bytes)
- I8m7XluZbbj10J53.xlsb (96,582 bytes)
- block.dll (312,832 bytes)
IMAGES
Shown above: Screenshot of the malicious email with sensitive information removed.
Shown above: Excel file attached to malicious email.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.