2017-11-02 - ADVENTURES WITH SMOKE LOADER

NOTICE:

ASSOCIATED FILES:

 

INFECTION SUMMARY

89.38.98[.]150/sZioajajaj.exe (Smoke Loader) --> Neutrino malware --> Lethic spambot infection

 

IMAGES


Shown above:  Smoke Loader infection traffic filtered in Wireshark.

 


Shown above:  Alerts from Smoke Loader infection traffic on Security Onion using Sguil with Suricata and the EmergingThreats Pro (ETPRO) ruleset.

 


Shown above:  Neutrino malware infection traffic filtered in Wireshark.

 


Shown above:  Neutrino pcap filtered to show some of the post-infection IPs/ports for Lethic spambot activity,

 


Shown above:  Alerts from the Neutrino & Lethic spambot traffic on Security Onion using Sguil with Suricata and the EmergingThreats Pro (ETPRO) ruleset.

 


Shown above:  TCP stream of Lethic spambot traffic.

 

DETAILS

NOTES:

 

DOMAINS OR URLS TO BLOCK:

 

INITIAL MALWARE - SHARIK/SMOKE LOADER:

 

SHARIK/SMOKE LOADER TRAFFIC:

Start date/time: 2017-11-02 at 17:20 UTC

 

ASSOCIATED EMERGING THREATS (ET) AND ETPRO ALERTS:

 

FOLLOW-UP MALWARE - NEUTRINO MALWARE:

 

NEUTRINO MALWARE INFECTION TRAFFIC:

 

ASSOCIATED EMERGING THREATS (ET) AND ETPRO ALERTS:

 

FOLLOW-UP MALWARE FROM NEUTRINO MALWARE INFECTION - ALL LETHIC SPAMBOT MALWARE BINARIES:

 

LETHIC SPAMBOT INFECTION TRAFFIC:

 

ASSOCIATED EMERGING THREATS (ET) AND ETPRO ALERTS:

 

Click here to return to the main page.