2015-03-23 - ANGLER EK PUSHES RANSOMWARE

NOTICE:

ASSOCIATED FILES:

 

NOTES:


Shown above: Partial view of lock screen generated by the malware payload from Angler EK.

 

CHAIN OF EVENTS

ANGLER EK:

POST-INFECTION TRAFFIC:

 

ALERTS

Signature hits from the Emerging Threats and ETPRO rulesets using Suricata on Security Onion (without ET POLICY or ET INFO events):

Signature hits from the Talos (Sourcefire VRT) ruleset using Snort 2.9.7.2 on Debian 7:

 

MALWARE FROM THE INFECTED HOST

File name:  C:\ProgramData\ADC290768.cpp   (decrypted Angler EK malware payload, a DLL file)
File size:  237,568 bytes
MD5 hash:  95a0cafb24e9edcbdb52e685f7b5a5b3
Detection ratio:  22 / 57
First submission:  2015-03-23 18:56:43 UTC
VirusTotal link:  https://www.virustotal.com/en/file/d46699b085adb4e235c80c5359cff975c5b5e3f9e136400d89ad29af8fad4c72/analysis/

File name:  C:\ProgramData\C328CD902.zot   (another DLL)
File size:  358,912 bytes
MD5 hash:  2479dd9b68bd7c137edae000c728f86d
Detection ratio:  9 / 57
First submission:  2015-03-23 18:59:18 UTC
VirusTotal link:  https://www.virustotal.com/en/file/fe3598d7ce646329c95d17f8a6706a4a8f758e780f426b4ec527ff33c4df3b55/analysis/

 

Click here to return to the main page.