2016-03-11 - ANGLER EK FROM 91.227.68.180

PCAP AND MALWARE:

 

NOTES:


Shown above:  Example of the "early Darkleech/pseudo-Darkleech" style injected script in page from compromised site.

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:


Shown above:  Pcap of today's traffic filtered in Wireshark.

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.