2014-05-01 - ANGLER EK FROM 64.120.207[.]245 - JDG.GOGEXYCOHUNSDS[.]NET

NOTICE:

ASSOCIATED FILES:

NOTE: This one's a relatively quick post for situational awareness.  I didn't extract or deobfuscate any of the malware from the pcap.

PREVIOUS ANGLER EK:

 

CHAIN OF EVENTS

 

ALERTS

ALERTS FOR THE INFECTION TRAFFIC (from Sguil on Security Onion)

 

FINAL NOTES

Click here to return to the main page.