2015-11-09 - NUCLEAR EK FROM 178.62.8[.]117 SENDS ANDROMEDA/CTB-LOCKER

NOTICE:

ASSSOCIATED FILES:


Shown above: Desktop background from infected Windows host.

 

TRAFFIC

ASSOCIATED DOMAINS:


Shown above: Events generated after using tcpreplay on the pcap in Security Onion.

 

COMPROMISED WEBSITE AND REDIRECT:


Shown above: Injected script in page from compromised website.


Shown above: Redirect URL leading to Nuclear EK landing page.

 

NUCLEAR EK:

 

POST-INFECTION TRAFFIC:

 

PRELIMINARY MALWARE ANALYSIS

NUCLEAR EK ARTIFACTS:

 

ARTIFACTS RETRIEVED FROM THE INFECTED HOST:

 

Click here to return to the main page.