2016-06-15 - SUNDOWN EK FROM 45.63.26.202 SENDS FLASH AND SILVERLIGHT EXPLOITS

ASSOCIATED FILES:

  • 2016-06-15-Sundown-EK-traffic.pcap   (530,934 bytes)
  • 2016-06-15-Sundown-EK-flash-exploit.swf   (38,603 bytes)
  • 2016-06-15-Sundown-EK-landing-page-first-example.txt   (89,128 bytes)
  • 2016-06-15-Sundown-EK-landing-page-second-example.txt   (95,001 bytes)
  • 2016-06-16-Sundown-EK-payload.exe   (126,976 bytes)
  • 2016-06-16-Sundown-EK-silverlight-exploit.zip   (20,412 bytes)

 

NOTES:

  • 2015-04-24: EmergingThreats creates rules to detect Sundown EK.   (link)
  • 2015-06-08: Malware Don't Need Coffee blog - Fast look at Sundown EK.   (link)
  • 2015-06-18: Virus Bulletin - Beta exploit pack: one more piece of crimeware for the infection road!   (link)
  • 2015-06-25: Proofpoint blog: Sundown EK Spreads LuminosityLink RAT: Light After Dark.   (link)
  • 2015-08-24: Symantec blog - Sundown exploit kit adds IE exploit before any other kit.   (link)
  • 2015-12-27: Threatglass post with malicious traffic caused by foromtb.com.   (link)
  • 2015-12-27: Jack at Malwarefor.me examines Sundown EK sending Neutrino malware based on the previous Threatglass post.   (link)
  • 2016-06-15: Discussion on Twitter initiated by Jérôme Segura.   (link)

Shown above:  A note about Sundown EK shamelessly stealing from other EKs.

 

TRAFFIC

SUNDOWN EK DOMAIN NAMES FROM THE TRAFFIC:

 

IMAGES


Shown above:  Injected script in page from compromised website leading to Sundown EK.

 


Shown above:  Sundown EK traffic filtered in Wireshark.

 


Shown above:  One of the Sundown EK landing pages.

 


Shown above:  Sundown EK sends Flash exploit.

 


Shown above:  Sundown EK sends Silverlight exploit.

 


Shown above:  Sundown EK sends malware payload.

 


Shown above:  Notable alerts on the infection traffic in Security Onion using Suricata and the EmergingThreats Pro ruleset.

 


Shown above:  Notable alerts on the traffic in Snort using the Snort subscriber ruleset.

 

FINAL NOTES

Once again, here are the associated files:

 

Click here to return to the main page.