GOLD_CABIN__2021__taa551-treatresearch_final-1.15.21.pdf
ID: 29a5f4d3-8439-49c7-b60e-0dc5986c8e19
STIX ID: report--29a5f4d3-8439-49c7-b60e-0dc5986c8e19
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2021-01-15
Last Modified Date: 2021-01-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mimecast/Nettitude analysis of TA551/Shathak describes a targeted phishing campaign (Japanese-language lures) using password-protected ZIPs and macro-enabled DOCX droppers that decode a ROT13 payload to write an HTA, which downloads a second-stage DLL executed via regsvr32; the DLL retrieves RC4-encrypted payloads hidden in PNG IDAT chunks (IcedID), performs VM/timing checks and C2 fingerprinting, and contains persistence/defense-evasion logic — the report includes IOCs, domain lists, sandbox references and MITRE TTP mappings.
