2021-12-13 (MONDAY) - FILES FOR AN ISC DIARY (CONTACT FORMS ICEDID INFECTION)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
NOTES:
- In the reference below, I mistakenly reported the BackConnect and Anubis VNC traffic as "DarkVNC" for the Internet Storm Center (ISC).
- I've fixed this blog post and the material to show the correct activity.
- For more on Backconnect, see: https://www.netresec.com/?page=Blog&month=2022-10&post=IcedID-BackConnect-Protocol
- For more on Anubis VNC, see: https://blog.nviso.eu/2023/03/20/icedids-vnc-backdoors-dark-cat-anubis-keyhole/
REFERENCE:
- The associated ISC diary is How the "Contact Forms" campaign tricks people.
ASSOCIATED FILES:
- 2021-12-13-Contact-Forms-IcedID-with-Cobalt-Strike-and-BackConnect-and-Anubis-VNC.pcap.zip 44.7 MB (44,738,672 bytes)
- 2021-12-13-IcedID-and-Cobalt-Strike-malware-and-artifacts.zip 1.4 MB (1,408,920 bytes)
IMAGES
Shown above: Screenshot of video from the decoded VNC traffic.
Click here to return to the main page.