2017-04-14 - GATE LEADS TO TERROR EK, SAME GATE LATER LEADS TO RIG EK

ASSOCIATED FILES:

  • 2017-04-14-Rig-EK-traffic.pcap   (297,015 bytes)
  • 2017-04-14-Terror-EK-traffic.pcap   (358,964 bytes)
  • 2017-04-14-Rig-EK-artifact-o32.tmp.txt   (1,141 bytes)
  • 2017-04-14-Rig-EK-flash-exploit.swf   (19,110 bytes)
  • 2017-04-14-Rig-EK-landing-page.txt   (117,916 bytes)
  • 2017-04-14-Rig-EK-payload-dcwq06dn.exe   (192,000 bytes)
  • 2017-04-14-Terror-EK-flash-exploit-1-of-3.swf   (51,109 bytes)
  • 2017-04-14-Terror-EK-flash-exploit-2-of-3.swf   (14,869 bytes)
  • 2017-04-14-Terror-EK-flash-exploit-3-of-3.swf   (4,078 bytes)
  • 2017-04-14-Terror-EK-landing-page.txt   (23,799 bytes)
  • 2017-04-14-Terror-EK-payload-rad364F6.tmp.exe   (192,000 bytes)
  • 2017-04-14-Terror-EK-second-page.txt   (7,778 bytes)

NOTES:

 

TRAFFIC


Shown above:  Traffic from the 1st infection filtered in Wireshark   (Terror EK).

 


Shown above:  Traffic from the 2nd infection filtered in Wireshark   (Rig EK).

 

ASSOCIATED DOMAINS:

 

FILE HASHES

FLASH EXPLOITS:

PAYLOADS:

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.