2014-09-23 - ANGLER EK FROM 66.172.12[.]231 - ASD.BLOUSESTRAIGHTAWAY[.]US

NOTICE:

NOTE:

ASSOCIATED FILES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

COMPROMISED WEBSITE AND REDIRECT:

 

ANGLER EK:

 

POST-INFECTION TRAFFIC:

 

PRELIMINARY MALWARE ANALYSIS

FLASH EXPLOIT:

File name:  2014-09-23-Angler-EK-flash-exploit.swf
File size:  76,984 bytes
MD5 hash:  dfaf6485ccfaa677cb9246b2adb413ef
Detection ratio:  1 / 55
First submission:  2014-09-23 11:35:57 UTC
VirusTotal link:  https://www.virustotal.com/gui/file/61d19c16272cdb85c7eca12cacd63cc4c37c312e2f5ec5cb922b17222775d2b9

 

MALWARE PAYLOAD:

File name:  2014-09-23-Angler-EK-malware-payload.exe
File size:  356,352 bytes
MD5 hash:  2142016b7491362835af160265cb59c0
Detection ratio:  27 / 55
First submission:  2014-09-23 22:30:40 UTC
VirusTotal link:  https://www.virustotal.com/gui/file/5aae995716e04bdb69eb0c5739002d53951633203bd25580cb13389eab3dd2cd

 

ALERTS

Emerging Threats and ETPRO rulesets from Sguil on Security Onion (not including ET INFO, ET POLICY, and other more common rules):

 

IMAGES FROM THE INFECTION

Popup in page from compromised website:

 

Injected script in page from compromised site leads to Angler EK:

 

Click here to return to the main page.