2015-08-07 - RIG EK FROM 46.30.46.24 - ADD.ELLICOTTVILLEREALESTATE.COM

PCAP AND MALWARE:

 

TRAFFIC

ASSOCIATED DOMAINS:

 

COMPROMISED WEBSITE AND REDIRECT:

 

RIG EK:

 

POST-INFECTION TRAFFIC:

 

PRELIMINARY MALWARE ANALYSIS

FLASH EXPLOIT

File name:  2015-08-07-Rig-EK-flash-exploit.swf
File size:  38.7 KB ( 39,593 bytes )
MD5 hash:  b34e4ebba88d5c226b5a126106b2daf8
SHA1 hash:  a4a509f7a0ff18ce671263127af61620f7921180
SHA256 hash:  aa5bfdef62a60f1d59dfabd8aa93e2a7074de42d0d5db0a71d0f6a8c917d4734
Detection ratio:  1 / 55
First submission:  2015-08-03 21:44:25 UTC
VirusTotal link:  https://www.virustotal.com/en/file/aa5bfdef62a60f1d59dfabd8aa93e2a7074de42d0d5db0a71d0f6a8c917d4734/analysis/

 

MALWARE PAYLOAD

File name:  2015-08-07-Rig-EK-malware-payload.exe
File size:  364.0 KB ( 372,736 bytes )
MD5 hash:  2189833a78d9e21f1579edfa459e4141
SHA1 hash:  67b5c67ebc26f779ada08470e30566bc168e74eb
SHA256 hash:  07db4cdee00a6a72050bac48d40d1c68d447591b86400bc9efe096c9791a7ddc
Detection ratio:  3 / 53
First submission:  2015-08-07 13:14:25 UTC
VirusTotal link:  https://www.virustotal.com/en/file/07db4cdee00a6a72050bac48d40d1c68d447591b86400bc9efe096c9791a7ddc/analysis/
Malwr link:  https://malwr.com/analysis/NDc4NTc0YWNlNjZiNDA5YmFjYzc1Nzg1NWExMzBhMjc/
Hybrid-Analysis link:  https://www.hybrid-analysis.com/sample/07db4cdee00a6a72050bac48d40d1c68d447591b86400bc9efe096c9791a7ddc?environmentId=1

 

 

SNORT EVENTS

Suricata using the Emerging Threats open ruleset on Security Onion (not including ET INFO or ET POLICY rules):

 

Snort 2.9.7.3 using Talos Snort Registered Rules on Debian 7:

 

IMAGES FROM THE TRAFFIC

Malicious script in page from compromised website:

 

Gate URL redirecting to the Rig EK landing page:

 

Rig EK landing page:

 

Rig EK sends Flash exploit:

 

Rig EK sends malware payload.  EXE file is XOR-ed with the ASCII string nkiOaWsg

 

First domain for the post-infection traffic returns 404 Not Found:

 

Second domain for the post-infection traffic seems to work:

 

FINAL NOTES

Once again, here are the associated files:

The ZIP file is password-protected with the standard password.  If you don't know it, email me at admin@malware-traffic-analysis.net and ask.

Click here to return to the main page.