2014-01-27 - GOON EK

ASSOCIATED FILES:

NOTICE:

ASSOCIATED FILES:

 

PREVIOUS ENTRIES ON GOON EK TRAFFIC

This time, the Goon EK domain used a Microsoft Silverlight exploit.

 

TRAFFIC

ALERTS

 

ASSOCIATED DOMAINS

 

INFECTION CHAIN OF EVENTS

NOTE: The pcap also has the following post-infection callback traffic:

 

File name:  2014-01-27-Goon-EK-silverlight-exploit.xap
File size:  7,039 bytes
MD5 hash:  8e7a86c7d27d1eea7df0534b8879022f
Virus Total link:  https://www.virustotal.com/en/file/1440714aeae4db23b3536cf88041d5bb84edd86e9f851b747df958f64293156a/analysis/
Detection ratio:  2 / 49
First submission to VirusTotal:  2014-01-26 15:29:10 UTC

 

File name:  2014-01-27-Goonk-EK-malware-payload.exe
File size:  222,208 bytes
MD5 hash:  d343946f3100566fa9949dd0d5ad2fac
Virus Total link:  https://www.virustotal.com/en/file/ea7c1b1e79b041f9a76e92d7fc6bfd26150f0a58eb43ebd9c0e12eff55490370/analysis/
Detection ratio:  26 / 50
First submission to VirusTotal:  2014-01-28 19:51:30 UTC

 

File name:  2014-01-27-additional-malware.exe
File size:  87,170 bytes
MD5 hash:  dcc1f720310928b86de4c7efe19866a7
Virus Total link:  https://www.virustotal.com/en/file/1a111faf9e50408f5fa9d9150694b86669dbfba2e768041394855780c0cd0936/analysis/
Detection ratio:  33 / 50
First submission to VirusTotal:  2014-02-01 02:40:00 UTC

 

Click here to return to the main page.