2015-04-30 - ANGLER EK SENDS ALPHA CRYPT RANSOMWARE

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

ANGLER EK:

 

POST-INFECTION TRAFFIC:

 

ALERTS

Signature hits from the Emerging Threats and ETPRO rulesets using Sguil on Security Onion (without ET POLICY or ET INFO events):

Significant signature hits from the Talos (Sourcefire VRT) ruleset using Snort 2.9.7.2 on Debian 7:

 

PRELIMINARY MALWARE ANALYSIS

FLASH EXPLOIT:

File name:  2015-04-30-Angler-EK-Flash-exploit.swf
File size:  55,255 bytes
MD5 hash:  7d876df50581deb711df9af0029f64e4
Detection ratio:  2 / 57
First submission to VirusTotal:  2015-04-29 16:07:35 UTC<

 

MALWARE PAYLOAD (ALPHA CRYPT RANSOMWARE):

File name:  2015-04-30-Angler-EK-payload-Alpha-Crypt-ransomware.exe
File size:  420,864 bytes
MD5 hash:  1c71d29bede55f34c9b17e24bd6a2a31
Detection ratio:  5 / 57
First submission to VirusTotal:  2015-04-30 00:40:49 UTC

 

Click here to return to the main page.