2017-12-01 - FAKE ANTI-VIRUS PAGE FROM EITEST CAMPAIGN

NOTICE:

ASSOCIATED FILES:

  • 2017-12-01-EITest-campaign-fake-av-page-traffic.pcap   (316,234 bytes)
  • 2017-12-01-EITest-campaign-fake-av-page-audio.mp3   (262,144 bytes)
  • 2017-12-01-EITest-campaign-fake-av-page-html.txt   (9,746 bytes)
  • 2017-12-01-page-from-accutech_net-with-injected-EITest-campaign-script.txt   (17,843 bytes)

 

BACKGROUND:

 

WEB TRAFFIC BLOCK LIST

Indicators are not a block list.  If you feel the need to block web traffic, I suggest the following domains:

 

TRAFFIC


Shown above:  Injected script in page from compromised site.

 


Shown above:  Network traffic filtered in Wireshark.

 

NETWORK TRAFFIC FROM MY LAB HOST:

 

IMAGES


Shown above:  Fake anti-virus page.

 


Shown above:  Pop-up from fake anti-virus page.

 

Click here to return to the main page.