2021-09-03 (FRIDAY) - GULOADER FOR POSSIBLE REMCOS RAT

NOTICE:

ASSOCIATED FILES:

NOTES:

 


Shown above:  Chain of events for this infection.

 


Shown above:  Screenshot of the email.

 


Shown above:  Screenshot of the attachment opened in Microsoft Excel.

 


Shown above:  Traffic from the infection filtered in Wireshark

 


Shown above:  GuLoader saved to the infected Windows host.

 

Click here to return to the main page.