2015-07-20 - NUCLEAR EK SENDS TESLACRYPT 2.0 RANSOMWARE

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

NUCLEAR EK:

 

POST-INFECTION TRAFFIC:

 

IDS ALERTS

Significant signature hits from the Emerging Threats and ETPRO rulesets using Sguil on Security Onion:

 

PRELIMINARY MALWARE ANALYSIS

FLASH EXPLOIT:

File name:  2015-07-20-Nuclear-EK-flash-exploit.swf
File size:  23,803 bytes
MD5 hash:  9d981efe8be1fe0a54937652cce94013
SHA256 hash:  8740775f8aea01d4e3013863ba4a8e1a553f89e71375530e7198865af2673488
Detection ratio:  1 / 55
First submission to VirusTotal:  2015-07-20 14:48:23 UTC

 

MALWARE PAYLOAD:

File name:  2015-07-20-Nuclear-EK-payload-TeslaCrypt-2.0-ransomware.exe
File size:  357,888 bytes
MD5 hash:  50fd967b39315d95f02127a2f05f6326
SHA256 hash:  8271d841b9971f04d6a48804d06ecd7185d71ed8546988b1697fbe01741a8572
Detection ratio:  7 / 55
First submission to VirusTotal:  2015-07-20 14:48:42 UTC

 

Click here to return to the main page.