2017-03-15 - PSEUDO-DARKLEECH RIG EK SENDS CERBER

ASSOCIATED FILES:

  • 2017-03-15-pseudoDarkleech-Rig-EK-sends-Cerber-1st-run.pcap   (797,089 bytes)
  • 2017-03-15-pseudoDarkleech-Rig-EK-sends-Cerber-2nd-run.pcap   (406,889 bytes)
  • 2017-03-12-pseudoDarkleech-Rig-EK-artifact-both-runs-o32.tmp.txt   (1,141 bytes)
  • 2017-03-15-Cerber_READ_THIS_FILE_KVGVA_.hta   (77,345 bytes)
  • 2017-03-15-Cerber_READ_THIS_FILE_L5KW_.jpeg   (1,975,631 bytes)
  • 2017-03-15-Cerber_READ_THIS_FILE_M0761P_.txt   (1,337 bytes)
  • 2017-03-15-page-from-jesuisanimateur.fr-with-injected-pseudoDarkleech-script-1st-run.txt   (157,692 bytes)
  • 2017-03-15-page-from-jesuisanimateur.fr-with-injected-pseudoDarkleech-script-2nd-run.txt   (156,494 bytes)
  • 2017-03-15-pseudoDarkleech-Rig-EK-1st-run-flash-exploit.swf   (14,956 bytes)
  • 2017-03-15-pseudoDarkleech-Rig-EK-1st-run-landing-page.txt   (117,920 bytes)
  • 2017-03-15-pseudoDarkleech-Rig-EK-1st-run-payload-Cerber-n0ofzkos.exe   (257,225 bytes)
  • 2017-03-15-pseudoDarkleech-Rig-EK-2nd-run-flash-exploit.swf   (14,942 bytes)
  • 2017-03-15-pseudoDarkleech-Rig-EK-2nd-run-landing-page.txt   (57,857 bytes)
  • 2017-03-15-pseudoDarkleech-Rig-EK-2nd-run-payload-Cerber-wyprkl4v.exe   (257,225 bytes)

 

DETAILS

 

ASSOCIATED DOMAINS:

 

FILE HASHES:

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.