2016-03-08 - PSEUDO-DARKLEECH ANGLER EK FROM 85.143.220.117

PCAP AND MALWARE:

 

NOTES:

 

TRAFFIC


Shown above:  Traffic from the pcap filtered in Wireshark.

ASSOCIATED DOMAINS:

 

IMAGES


Shown above:  Start of injected pseudo-Darkleech script in page from a compromised web site.

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.