2016-03-14 - ANGLER EK DATA DUMP

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

ASSOCIATED DOMAINS

GATES:

ANGLER EK:

POST-INFECTION FROM THE TESLACRYPT RANSOMWARE:

POST-INFECTION FROM THE EITEST ANGLER EK PAYLOAD:

 

MALWARE

READ: MD5 HASH - FILE NAME

 

IMAGES


Shown above:  Pcaps of today's traffic filtered in Wireshark.

 


Shown above:  Injected "admedia" script in page from compromised site (and translation of the hexadecimal script).

 


Shown above:  Start of injected pseudo-Darkleech script in page from compromised site.

 


Shown above:  End of injected pseudo-Darkleech script in page from compromised site.

 


Shown above:  Decrypt instructions from the TeslaCrypt malware.

 


Shown above:  Injected "EITest" script in page from compromised site.

 


Shown above:  Injected script from the third compromised site.

 


Shown above:  Same compromised site as the previous image, but different injected script 3 days prior.

 

Click here to return to the main page.