2016-03-07 - ANGLER EK DATA DUMP

PCAP AND MALWARE:

  • 2016-03-07-EITest-Angler-EK-after-dixonroofing.co.nz.pcap - 511.0 kB (511,038 bytes)
  • 2016-03-07-pseudo-Darkleech-Angler-EK-after-automufflersbrakes.com.pcap - 596.7 kB (596,693 bytes)
  • 2016-03-07-pseudo-Darkleech-Angler-EK-after-dstewartsales.com.pcap - 898.7 kB (898,683 bytes)
  • 2016-03-07-pseudo-Darkleech-Angler-EK-after-vediaud.net.pcap - 895.6 kB (895,551 bytes)

 

NOTES:

 

DOMAINS

GATES (REDIRECTS):

ANGLER EK:

TELSACRYPT POST-INFECTION TRAFFIC:

 

EXPLOITS/MALWARE

FLASH EXPLOITS SENT BY ANGLER EK (READ: MD5, FILE NAME):

MALWARE SENT BY ANGLER EK (READ: MD5, FILE NAME):

 

IMAGES


Shown above:  Traffic from the pcaps filtered in Wireshark.

 


Shown above:  Example of injected pseudo-Darkleech script in page from a compromised web site.

 


Shown above:  Injected script in page from a compromised site pointing to an "EITest" gate.

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.