2016-03-18 - ANGLER EK DATA DUMP

NOTICE:

ASSOCIATED FILES:

 

ASSOCIATED DOMAINS

ANGLER EK:

TESLACRYPT RANSOMWARE POST-INFECTION TRAFFIC FROM 2016-03-17:

TESLACRYPT RANSOMWARE POST-INFECTION TRAFFIC FROM 2016-03-18:

 

IMAGES


Shown above:  Pcaps for this blog entry's traffic filtered in Wireshark.

 


Shown above:  Injected script in page from compromised website on 2016-03-17.

 


Shown above:  Injected script in page from compromised website on 2016-03-18.

 


Shown above:  Start of pseudo-Darkleech injected script in page from compromised website on 2016-03-18.

 


Shown above:  Decrypt instructions from TeslaCrypt samples on 2016-03-18.

 

Click here to return to the main page.