2016-03-09 - ANGLER EK DATA DUMP

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

DOMAINS

GATES (REDIRECTS):

ANGLER EK:

TELSACRYPT RANSOMWARE POST-INFECTION TRAFFIC:

 

EXPLOITS/MALWARE

FLASH EXPLOITS SENT BY ANGLER EK (READ: MD5, FILE NAME):

TESLACRYPT RANSOMWARE SENT BY ANGLER EK (READ: MD5, FILE NAME):

 

IMAGES


Shown above:  Traffic from the pcaps filtered in Wireshark.

 


Shown above:  Start of injected pseudo-Darkleech script in page from a compromised web site.

 


Shown above:  Injected script in page from a compromised site pointing to an "EITest" gate.

 


Shown above:  Start of injected pseudo-Darkleech script in page from a compromised web site.

 

Click here to return to the main page.