2021-01-05 (TUESDAY) - PURPLEFOX EK PUSHES NUGGETPHANTOM MALWARE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES
- 2021-01-05-IOCs-from-PurpleFox-EK-and-NuggetPhantom.txt.zip kB (1,554 bytes)
- 2021-01-05-IOCs-from-PurpleFox-EK-and-NuggetPhantom.txt (2,822 bytes)
- 2021-01-05-PurpleFox-EK-and-post-infection-traffic.pcap.zip 7.2 MB (7,169,380 bytes)
- 2021-01-05-PurpleFox-EK-and-post-infection-traffic.pcap (9,546,691 bytes)
- 2021-01-05-ET-alerts-for-PurpleFox-EK-infection.zip 2.2 MB (2,211,832 bytes)
- 2021-01-05-ET-alerts-for-PurpleFox-EK-infection.jpg (2,344,062 bytes)
- 2021-01-05-ET-alerts-for-PurpleFox-EK-infection.txt (6,574 bytes)
- 2021-01-05-PurpleFox-EK-malware-and-artifacts.zip 3.4 MB (3,430,472 bytes)
- 2021-01-05-mythinkenergy.club--key-F6A5DDD7C719FB934.txt (30,884 bytes)
- 2021-01-05-mythinkenergy.club-base64.min.js.txt (215 bytes)
- 2021-01-05-rawcdn.githack.com-M0021.cab.bin (1,941,603 bytes)
- 2021-01-05-rawcdn.githack.cyou-M002.jpg.bin (1,019,904 bytes)
- 2021-01-05-rawcdn.githack.cyou-up.php-key-5.txt (31,499 bytes)
- 2021-01-05-rawcdn.githack.cyou-up.php-key-6.bin (1,019,904 bytes)
- 2021-01-05-rawcdn.githack.cyou-up.php-key-8.txt (719,288 bytes)
NOTES:
- I generated PurpleFox EK traffic based on info from @nao_sec's tweet on 2020-12-29: https://twitter.com/nao_sec/status/1343918070989877252
- In this case, PurpleFox EK sent NuggetPhantom malware.
- For more info about NuggetPhantom, you can download a 2018 report published by NSFOCUS from this page.
IMAGES
Shown above: Alerts from Sguil in Security Onion using Suricata and the EmergingThreats Pro (ETPRO) ruleset. Click on the above picture for a higher-resolution image.
Shown above: Traffic from the infection filtered in Wireshark. Click on the above picture for a higher-resolution image.
Shown above: Filtering in Wireshark to show scanning targeting TCP port 445. Click on the above picture for a higher-resolution image.
Click here to return to the main page.