2015-10-08 - THREE EXAMPLES OF NUCLEAR EK FROM 188.226.215.37

PCAP AND MALWARE:

 

NOTES:

 

CHAIN OF EVENTS

EXAMPLE 1:

 

EXAMPLE 2:

 

EXAMPLE 3:

 

FINAL NOTES

Once again, here's the PCAP of the traffic and ZIP file of the malware:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.