2016-03-23 - TWO EXAMPLES OF ANGLER EK

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

ASSOCIATED DOMAINS

FIRST INFECTION:

SECOND INFECTION:

 

MALWARE AND ARTIFACTS

Contents of today's archive with the malware and artifacts:

 

IMAGES


Shown above:  Traffic from the infections filtered in Wireshark.

 


Shown above:  Start of pseudo-Darkleech injected script in page from first compromised website.

 


Shown above:  Other injected script in page from first compromised website (did not go to an EK).

 


Shown above:  Injected script in page from second compromised website.

 


Shown above:  Decrypt instructions from today's TeslaCrypt ransomware samples.

 

Click here to return to the main page.