2014-04-04 - FIESTA EK

ASSOCIATED FILES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS

INFECTION CHAIN OF EVENTS

 

PRELIMINARY MALWARE ANALYSIS

SILVERLIGHT EXPLOIT CVE-2013-0074

File name:  2014-04-04-Fiesta-EK-silverlight-exploit.xap
File size:  5.3 KB ( 5396 bytes )
MD5 hash:  85f7d443373e6150333752ce8ba14388
Detection ratio:  18 / 51
First submission:  2014-04-01 00:22:32 UTC
VirusTotal link:  https://www.virustotal.com/en/file/977514f84e79294e2c28664beeb5d629263eef7d40ca6919d0396e7e8dd9c9d4/analysis/

 

JAVA EXPLOIT CVE-2012-0507

File name:  2014-04-04-Fiesta-EK-java-exploit.jar
File size:  4.8 KB ( 4915 bytes )
MD5 hash:  b06c4c3e58c717a73ff185c87c290cd6
Detection ratio:  12 / 51
First submission:  2014-04-02 18:37:33 UTC
VirusTotal link:  https://www.virustotal.com/en/file/adcf72959fc94988c636bf8889cc04843b6b23dcaa584c5d83bb0e955284f84a/analysis/

 

MALWARE PAYLOAD

File name:  2014-04-04-Fiesta-EK-malware-payload.exe
File size:  163.3 KB ( 167217 bytes )
MD5 hash:  7ce240ccd4d8fa71f61cedfcb446af3e
Detection ratio:  11 / 49
First submission:  2014-04-04 08:17:45 UTC
VirusTotal link:  https://www.virustotal.com/en/file/d5f2b62e7a799c926c0a9862b2afdb06640c6def88f2be22c9d3c54ee4d052ff/analysis/
Malwr link:  https://malwr.com/analysis/ODk1Y2YwOTQwMGY1NDdlMWEzZTZmMWRiYTU0YTBiZmY/

 

SNORT EVENTS

SNORT EVENTS FROM THE INFECTION TRAFFIC (from Sguil on Security Onion)

 

HIGHLIGHTS FROM THE TRAFFIC

Embedded javascript in the infected web page:

 

Redirect:

 

Fiesta EK delivers CVE-2013-2551 IE exploit:

 

CVE-2013-2551 IE exploit delivers EXE payload:

 

Fiesta EK delivers CVE-2013-0074 Silverlight exploit:

 

CVE-2013-0074 Silverlight exploit delivers EXE payload:

 

Fiesta EK delivers CVE-2012-0507 Java exploit:

 

CVE-2012-0507 Java exploit delivers EXE payload:

 

FINAL NOTES

Once again, here are links for the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.