2017-07-23 - EITEST HOFLERTEXT POPUP SENDS MOLE RANSOMWARE
ASSOCIATED FILES:
- Zip archive of the pcap: 2017-07-23-EITest-campaign-pcaps.zip 322 kB (322,197 bytes)
- 2017-07-23-EITest-HoflerText-popup-sends-Mole-ransomware-1st-run.pcap (302,477 bytes)
- 2017-07-23-EITest-HoflerText-popup-sends-Mole-ransomware-2nd-run.pcap (314,870 bytes)
- 2017-07-23-EITest-tech-support-scam-traffic.pcap (112,161 bytes)
- Zip archive of the artifacts and malware: 2017-07-23-EITest-campaign-artifacts-and-malware.zip 290 kB (289,655 bytes)
- 2017-07-23-1st-run-Font_Chrome.exe (174,080 bytes)
- 2017-07-23-2nd-run-Font_Chrome.exe (153,088 bytes)
- 2017-07-23-Mole-ransomware_HELP_INSTRUCTION.TXT (1,554 bytes)
- 2017-07-23-fake-Microsoft-AV-page-from-securityfalse.ga.txt (4,374 bytes)
- 2017-07-23-page-from-one-hour.fr-with-injected-HoeflerText-script-1st-run.txt (124,550 bytes)
- 2017-07-23-page-from-one-hour.fr-with-injected-HoeflerText-script-2nd-run.txt (124,550 bytes)
- 2017-07-23-page-from-one-hour.fr-with-injected-tech-support-scam-script.txt (79,597 bytes)
NOTES:
- The last time I saw the HoelferText popup, it was sending Spora ransomware (link), but now it's Mole ransomware.
- At this point, we're only seeing tech support scams and HoeflerText popups from the EITest campaign.
- For more information, see information on the EITest campaign in the Unit 42 blog titled: Decline in Rig Exploit Kit.
Shown above: Updated flow chart reflecting today's traffic from the EITest campaign.
TRAFFIC
Shown above: Screenshot of the traffic filtered in Wireshark for the HoeflerText popup and Mole ransomware.
Shown above: Screenshot of the traffic filtered in Wireshark for the tech support scam.
ASSOCIATED DOMAINS (EITEST - HOEFLERTEXT POPUP):
- one-hour.fr - compromised website
- 176.223.207.41 port 80 - clinicalpsychology.psiedu.ubbcluj.ro - GET /book1.php - [redirect]
- 213.32.70.49 port 80 - 213.32.70.49 - POST /info-statics.php - [Mole ransomware callback]
- s u p p o r t x x g b e f d 7 c . o n i o n - Tor domain from the decyption instructions