2015-02-10 - ANGLER EK FROM 151.80.94[.]250

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

ASSOCIATED DOMAINS

 

CHAIN OF EVENTS

COMPROMISED WEBSITE AND ANGLER EK:

 

POST-INFECTION TRAFFIC:

 

POST-INFECTION CLICK FRAUD TRAFFIC BEGINS:

 

ANGLER EK HAPPENS AGAIN DURING THE POST-INFECTION TRAFFIC:

 

ALERTS

Signature hits from the Emerging Threats and ETPRO rulesets using Sguil on Security Onion (without ET POLICY or ET INFO events):

Significant signature hits from the Talos (Sourcefire VRT) ruleset using Snort 2.9.7.0 on Debian 7:

 

SCREENSHOT FROM THE TRAFFIC

Iframe in malicious JavaScript from compromised website pointing to Angler EK landing page:

 

Click here to return to the main page.