2015-10-18 - ANGLER EK ACTIVITY

NOTICE:

ASSSOCIATED FILES:

 

IMAGES


Shown above:  Results in Security Onion after using tcpreplay on the pcap.

 


Shown above:  Script injected into pages from the compromised website.

 


Shown above:  First pcap, filtered in Wireshark on HTTP requests.

 


Shown above:  Second pcap, filtered in Wireshark on HTTP requests.

 


Shown above:  Third pcap, filtered in Wireshark on HTTP requests.

 

ASSOCIATED DOMAINS:

 

MALWARE RETRIEVED FROM ONE OF THE INFECTED HOSTS

 

Click here to return to the main page.