2014-04-01 - FIESTA EK - 3 EXAMPLES

ASSOCIATED FILES:

NOTES:

 

CHAIN OF EVENTS

FIRST FIESTA EK INFECTION - 31 MAR 2014

 

SECOND FIESTA EK INFECTION - 31 MAR 2014

 

THIRD FIESTA EK INFECTION - 01 APR 2014

 

PRELIMINARY MALWARE ANALYSIS

SILVERLIGHT EXPLOIT SEEN IN ALL THREE INFECTIONS

File name:  2014-03-31-Fiesta-EK-silverlight-exploit.xap
File size:  5.3 KB ( 5396 bytes )
MD5 hash:  85f7d443373e6150333752ce8ba14388
Detection ratio:  0 / 51
First submission:  2014-04-01 00:22:32 UTC
VirusTotal link:  https://www.virustotal.com/en/file/977514f84e79294e2c28664beeb5d629263eef7d40ca6919d0396e7e8dd9c9d4/analysis/

 

JAVA EXPLOIT SEEN IN ALL THREE INFECTIONS

File name:  2014-03-31-Fiesta-EK-java-exploit.jar
File size:  7.3 KB ( 7460 bytes )
MD5 hash:  17575d806f5ad6eb1cfa951948f618c0
Detection ratio:  1 / 51
First submission:  2014-04-01 00:22:12 UTC
VirusTotal link:  https://www.virustotal.com/en/file/91578a8568e1d3f4b28fc87b9a4274923884b852d2190b51e53f828331d07082/analysis/

 

MALWARE PAYLOAD FOR BOTH INFECTIONS ON 31 MAR 2014

File name:  2014-03-31-Fiesta-EK-malware-payload.exe
File size:  288.0 KB ( 294912 bytes )
MD5 hash:  91f80ac5c63a8e609a521e3a174ce013
Detection ratio:  3 / 51
First submission:  2014-04-01 00:22:49 UTC
VirusTotal link:  https://www.virustotal.com/en/file/d28a9e727ce8e17104b1c1e04764b62177e0caba02783c730f1a973860de93de/analysis/
Malwr link:  https://malwr.com/analysis/OTQzNDgxYjMwMGU3NGU2MGIwMjM1YzcxMjQ4NGM1YmQ/

 

MALWARE PAYLOAD FOR 01 APR 2014

File name:  2014-04-01-Feista-EK-malware-payload.exe
File size:  140.2 KB ( 143581 bytes )
MD5 hash:  7d35095a22cec16a9470261861a59818
Detection ratio:  3 / 50
First submission:  2014-04-01 02:34:30 UTC
VirusTotal link:  https://www.virustotal.com/en/file/6ea1e25a549b3ae9b7c673ffb22fa9248ff3176827630ea22660c9123bcd1b57/analysis/
Malwr link:  https://malwr.com/analysis/NDdkNjYwNmMzYWU0NGJhZDhlN2U0YjJkMmMzYzA1YWE/

 

SNORT EVENTS

SNORT EVENTS FROM THE FIRST INFECTION ON 31 MAR 2014 (from Sguil on Security Onion)

 

SNORT EVENTS FROM THE SECOND INFECTION ON 31 MAR 2014

 

SNORT EVENTS FOR THE INFECTION TRAFFIC ON 01 APR 2014

 

SOME SCREENSHOTS FROM THE TRAFFIC

Embedded javascript or iframe from the infected web pages:

 

Redirects seen on 2014-03-31:

 

NOTE: The rest of the traffic is similar to what I've already posted several times for Fiesta EK.

 

FINAL NOTES

Once again, here are links for the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.