2019-06-28 - QUICK POST: FAKE UPDATES CAMPAIGN SENDS CHTHONIC

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

TRAFFIC


Shown above:  Fake Firefox update page with link to malicious download.

 


Shown above:  Some URLs for the fake Firefox update page.

 


Shown above:  The index (initial) page for the fake Firefox update.

 


Shown above:  Base64 string in the fake update index page represents a malicious zip file.

 


Shown above:  Name for the malicious zip file and other related script information.

 


Shown above:  The zip archive was automatically sent, even when I didn't press the green update button.

 


Shown above:  The malicious zip file and extracted .js file.

 


Shown above:  Traffic from running the .js file followed by Chthonic post-infection traffic.  Two reboots were noted during this infection.
Each line with www.msftncsi.com indicates where my infected Windows host rebooted.

 


Shown above:  HTTP POST request that sent a screen shot of my infected Windows host.

 

Click here to return to the main page.