2016-06-28 - EK DATA DUMP (NEUTRINO EK, RIG EK)

NOTICE:

ASSOCIATED FILES:

  • 2016-06-28-Neutrino-EK-after-mu-media_co_uk.pcap   (5,521,238 bytes)
  • 2016-06-28-Neutrino-EK-after-tonyattwood_com_au.pcap   (413,103 bytes)
  • 2016-06-28-Rig-EK-after-monavocatparis_fr.pcap   (200,657 bytes)
  • 2016-06-28-pseudoDarkleech-Neutrino-EK-after-airbornehydrography_com_pcap   (1,133,721 bytes)
  • 2016-06-28-pseudoDarkleech-Neutrino-EK-after-gennaroespositomilano_it.pcap   (1,385,884 bytes)
  • 2016-06-28-Neutrino-EK-flash-exploit-after-mu-media_co_uk.swf   (87,014 bytes)
  • 2016-06-28-Neutrino-EK-flash-exploit-after-tonwyattwood_com_au.swf   (90,037 bytes)
  • 2016-06-28-Neutrino-EK-landing-page-after-mu-media_co_uk.txt   (1,156 bytes)
  • 2016-06-28-Neutrino-EK-landing-page-after-tonwyattwood_com_au.txt   (1,003 bytes)
  • 2016-06-28-Neutrino-EK-payload-Gootkit-after-mu-media_co_uk.exe   (238,592 bytes)
  • 2016-06-28-Neutrino-EK-payload-Gootkit-after-tonwyattwood_com_au.exe   (238,592 bytes)
  • 2016-06-28-Rig-EK-flash-exploit-after-monavocatparis_fr.swf   (24,413 bytes)
  • 2016-06-28-Rig-EK-landing-page-after-monavocatparis_fr.txt   (5,304 bytes)
  • 2016-06-28-Rig-EK-payload-after-monavocatparis_fr.exe   (151,552 bytes)
  • 2016-06-28-page-from-airbornehydrography_com-with-injected-pseudoDarkleech-script.txt   (15,473 bytes)
  • 2016-06-28-page-from-gennaroespositomilano_it-with-injected-pseudoDarkleech-script.txt   (32,141 bytes)
  • 2016-06-28-page-from-monavocatparis_fr-with-injected-script-pointing-to-gate.txt   (12,860 bytes)
  • 2016-06-28-pseudoDarkleech-Neutrino-EK-flash-exploit-after-airbornehydrography_com.swf   (86,380 bytes)
  • 2016-06-28-pseudoDarkleech-Neutrino-EK-flash-exploit-after-gennaroespositomilano_it.swf   (89,145 bytes)
  • 2016-06-28-pseudoDarkleech-Neutrino-EK-landing-page-after-airbornehydrography_com.txt   (1,153 bytes)
  • 2016-06-28-pseudoDarkleech-Neutrino-EK-landing-page-after-gennaroespositomilano_it.txt   (1,012 bytes)
  • 2016-06-28-pseudoDarkleech-Neutrino-EK-payload-CryptXXX-ransomware.dll   (500,224 bytes)
  • 2016-06-28-CryptXXX-ransomware-decrypt-instructions.bmp   (3,686,454 bytes)
  • 2016-06-28-CryptXXX-ransomware-decrypt-instructions.html   (36,201 bytes)
  • 2016-06-28-CryptXXX-ransomware-decrypt-instructions.txt   (1,755 bytes)

 

TRAFFIC

ASSOCIATED DOMAINS:

 

IMAGES


Shown above:  Traffic from the first pcap filtered in Wireshark.

 


Shown above:  Alerts in Sguil after using tcpreplay on the first pcap in Security Onion with Suricata and the EmergingThreats Pro ruleset.

 


Shown above:  Traffic from the second pcap filtered in Wireshark.

 


Shown above:  Alerts in Sguil after using tcpreplay on the second pcap in Security Onion with Suricata and the EmergingThreats Pro ruleset.

 


Shown above:  Traffic from the third pcap filtered in Wireshark.

 


Shown above:  Alerts in Sguil after using tcpreplay on the third pcap in Security Onion with Suricata and the EmergingThreats Pro ruleset.

 


Shown above:  Traffic from the fourth pcap filtered in Wireshark.

 


Shown above:  Alerts in Sguil after using tcpreplay on the fourth pcap in Security Onion with Suricata and the EmergingThreats Pro ruleset.

 


Shown above:  Traffic from the fifth pcap filtered in Wireshark.

 


Shown above:  Alerts in Sguil after using tcpreplay on the fifth pcap in Security Onion with Suricata and the EmergingThreats Pro ruleset.

 

Click here to return to the main page.