2017-09-08 - EITEST CAMPAIGN FAKE AV ALERT / HOEFLERTEXT POPUP

ASSOCIATED FILES:

  • 2017-09-08-EITest-HoeflerText-popup-and-NetSupport-Manager-RAT-infection.pcap   (5,472,748 bytes)
  • 2017-09-08-EITest-fake-AV-page-for-tech-support-scam.pcap   (416,367 bytes)
  • 2017-09-08-DSAdaDSDA.js.txt   (4,630 bytes)
  • 2017-09-08-Font_Chrome.exe   (287,988 bytes)
  • 2017-09-08-NetSupport-Manager-RAT-installer-8vpv5aazn.jpg.exe   (3,804,458 bytes)
  • 2017-09-08-base62-string-for-NetSupport-Manager-RAT-installer.txt   (5,072,612 bytes)
  • 2017-09-08-client32.ini.txt   (969 bytes)
  • 2017-09-08-fake-AV-page-audio.mp3   (262,144 bytes)
  • 2017-09-08-fake-AV-page-from-angel07091.tk.txt   (4,374 bytes)
  • 2017-09-08-page-from-mintdentistryplano.com-with-injected-EITest-script-for-HoelferText-popup.txt   (179,923 bytes)
  • 2017-09-08-page-from-mintdentistryplano.com-with-injected-EITest-script-for-fake-AV-alert.txt   (134,848 bytes)

NOTES:


Shown above:  @killamjr's tweet.

 

SOME IMAGES


Shown above:  Current flow chart for activity caused by the EITest campaign.

 


Shown above:  Traffic for HoeflerText popup and NetSupport Manager RAT infection.

 


Shown above:  Traffic for fake anti-virus page and tech support scam.

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.