2016-02-23 - TWO EXAMPLES OF ADMEDIA ANGLER EK

PCAPS AND MALWARE:

 

NOTES:

 

DETAILS

DATE/TIME:  2016-02-23 21:33 UTC

 


Shown above:  Traffic from the first pcap filtered in Wireshark.

 


Shown above:  Injected script in page from the compromised website.

 

DATE/TIME:  2016-02-23 22:54 UTC

 


Shown above:  Traffic from the first pcap filtered in Wireshark.

 


Shown above:  Example of injected script in .js files from the compromised website.

 

$ md5sum *.exe

$ md5sum *.swf

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.