2014-06-30 - INFINITY EK FROM 188.65.113[.]171 - D7HOSTING[.]COM

NOTICE:

ASSOCIATED FILES:

 

CHAIN OF EVENTS

INFINITY EK:

POST-INFECTION TRAFFIC:

 

PRELIMINARY MALWARE ANALYSIS

FLASH EXPLOIT

File name:  2014-06-30-Infinity-EK-flash-exploit.swf
File size:  4,084 bytes
MD5 hash:  368bf49f08111c32fed060a61ba87bac
Detection ratio:  0 / 54
First submission:  2014-06-11 17:05:02 UTC

 

SILVERLIGHT EXPLOIT

File name:  2014-06-30-Infinity-EK-silverlight-exploit.xap
File size:  12,580 bytes
MD5 hash:  13110267b2764269c5e064cab95dca0c
Detection ratio:  0 / 54
First submission:  2014-06-28 13:21:02 UTC

 

MALWARE PAYLOAD

File name:  2014-06-30-Infinity-EK-malware-payload.exe
File size:  237,332 bytes
MD5 hash:  42fa88a8a004de2edeb088f2713b78e5
Detection ratio:  3 / 54
First submission:  2014-06-30 03:07:25 UTC

 

ALERTS

These Snort events were taken from Sguil on Security Onion using the default Emerging Threats rule set.  This list does not include the ET INFO or ET POLICY rules.

 

Click here to return to the main page.