2016-01-29 - ANGLER EK FROM 5.135.104[.]85 SENDS CRYPTOWALL RANSOMWARE

NOTICE:

ASSOCIATED FILES:

 

TRAFFIC

INFECTION TRAFFIC:

 

IP ADDRESSES AND DOMAINS FOR CALLBACK TRAFFIC FROM CRYPTOWALL RANSOMWARE SAMPLE:

 

IMAGES


Shown above:  Today's pcap filtered in Wireshark.

 


Shown above:  Today's CryptoWall ransomware sample infecting a Windows desktop.

 


Shown above:  CryptoWall ransomware callback traffic when I tested the malware sample.

 

Click here to return to the main page.