2015-01-08 - MALWARE HOSTED ON 82.244.160[.]22

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

COMPROMISED WEBSITES NOTED ON THREATGLASS:

 

EXAMPLES OF THE MALICIOUS IFRAME FROM THE COMPROMISED WEBSITE:

 

GET REQUESTS AND MALWARE

ASSOCIATED GET REQUESTS FOR .UNDO[.]IT DOMAINS:

 

ATTEMPTED MALWARE DOWNLOADS ACCORDING TO INFORMATION FROM THREATGLASS:

 

COPIES OF THE MALWARE I DOWNLOADED:

 

POST-INFECTION PCAPS:

 

POST-INFECTION TRAFFIC

POST-INFECTION TRAFFIC GENERATED BY NON-DIGITALLY-SIGNED MALWARE SAMPLE FROM 2015-01-03:

 

POST-INFECTION TRAFFIC GENERATED BY DIGITALLY-SIGNED MALWARE SAMPLE FROM 2015-01-04:

 

Click here to return to the main page.