2015-06-05 - ANGLER EK FROM 209.133.200.228 SENDS BEDEP AND NECURS

PCAP AND MALWARE:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

REDIRECT/GATE:

 

ANGLER EK:

 

POST-INFECTION TRAFFIC:

 

MALWARE

MALWARE FOUND ON THE INFECTED HOST:

 

IMAGES

Edited screenshot of Wireshark showing the traffic:

 

Signature hits from the Emerging Threats and ETPRO rulesets using Sguil on Security Onion (without ET POLICY or ET INFO events):

 

FINAL NOTES

Once again, here are the associated files:

Click here to return to the main page.