2014-03-13 - FIESTA EK DELIVERS CLICK FRAUD TROJAN

NOTICE:

ASSOCIATED FILES:

NOTES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS

INFECTION TRAFFIC:

POST-INFECTION CALLBACK TRAFFIC

 

PRELIMINARY MALWARE ANALYSIS

SILVERLIGHT EXPLOIT

File name:  2014-03-13-Fiesta-EK-silverlight-exploit.xap
File size:  5,242 bytes
MD5 hash:  e49ae100637dacd6a5b2864215bb13e5
Detection ratio:  0 / 50
First submission:  2014-03-14 04:28:49 UTC
VirusTotal link: https://www.virustotal.com/en/file/28e68f506986a0cf7f38110f274529f78f5d1491f2b78a3f7e84a4de64bc2c39/analysis/

 

JAVA EXPLOIT

File name:  2014-03-13-Fiesta-EK-java-exploit.jar
File size:  7,444 bytes
MD5 hash:  0d412aa73830d622e2aef154d4ef6b3d
Detection ratio:  5 / 50
First submission:  2014-03-13 19:27:15 UTC
VirusTotal link: https://www.virustotal.com/en/file/db17ffdda6f50170eb10973209b443aa3b3f45fb346db8d7d6088bc0a4b32d15/analysis/

 

MALWARE PAYLOAD

File name:  2014-03-13-Fiesta-EK-malware-payload.exe
File size:  147,456 bytes
MD5 hash:  f84d030c8efdd4feb2061b57faea8157
Detection ratio:  18 / 50
First submission:  2014-03-14 04:29:37 UTC
VirusTotal link: https://www.virustotal.com/en/file/be2c9730fcf5482e82d3bf99b895987b674163902b20b07e9b869ae25fd686e8/analysis/

 

ALERTS

ALERTS FOR INFECTION TRAFFIC (from Sguil on Security Onion)

 

HIGHLIGHTS FROM THE TRAFFIC

Embedded iframe in the infected web page - www.mappery[.]com/maps-United-States

 

Fiesa EK delivers silverlight exploit -
ihbctxjkp.myvnc[.]com/1je6bsz/?79fc0a0e56341fb544551058095a0450040151580403005e020a545253570504;5110411

 

Silverlight exploit delivers EXE payload -
ihbctxjkp.myvnc[.]com/1je6bsz/?4891ceae73f59ff05748520a5a5e555007000e0a5707515e010b0b0000535404;6

 

Fiesta EK delivers Java exploit -
ihbctxjkp.myvnc[.]com/1je6bsz/?351ac5e448ba11635c5a535a5a0e5101000d065a5757550f0606035000035205

 

Java exploit delivers EXE payload -
ihbctxjkp.myvnc[.]com/1je6bsz/?02969a35b8fea056534a5c0d005a0700030a0e0d0d03030e05010b075a570654;1;4

 

Callback traffic - HTTP POST over port 443 - 188.165.106[.]64:443/76EB1199A9E23152CD009BEC7C1C4EA0FA43D17388

 

Click here to return to the main page.