2021-07-02 (FRIDAY) - ASTAROTH/GUILDMA FROM BRAZIL MALSPAM

NOTICE:

ASSOCIATED FILES:

 


Shown above:  Screenshot from one of the emails.

 


Shown above:  Downloading malicious zip archive from the email link.

 


Shown above:  Extracted Windows shortcut from the downloaded zip archive.

 


Shown above:  Some of the traffic seen during this infection filtered in Wireshark.

 


Shown above:  Artifact from the infected Windows host.

 


Shown above:  Another artifact from the infected Windows host.

 


Shown above:  More artifacts and some malware found on the infected Windows host.

 


Shown above:  Shortcut in the Windows Startup menu folder to keep the infection persistent.

 

Click here to return to the main page.