ASSOCIATED FILES:
NOTES:

Shown above: Screenshot of a Word doc with macros for TA551 (new template started today).

Shown above: Traffic from an infection filtered in Wireshark.

Shown above: Example of installer DLL saved to the victim's host.

Shown above: Example of initial IcedID EXE created by installer DLL.

Shown above: PNG file with encoded data created after the initial EXE is run.

Shown above: Example of IcedID EXE persistent through scheduled task.
Click here to return to the main page.