2015-04-30 - ANGLER EK DELIVERS ALPHA CRYPT RANSOMWARE

ASSOCIATED FILES:

 

NOTES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

ANGLER EK:

 

POST-INFECTION TRAFFIC:

 

SNORT EVENTS

Signature hits from the Emerging Threats and ETPRO rulesets using Sguil on Security Onion (without ET POLICY or ET INFO events):

Significant signature hits from the Talos (Sourcefire VRT) ruleset using Snort 2.9.7.2 on Debian 7:

 

PRELIMINARY MALWARE ANALYSIS

FLASH EXPLOIT:

File name:  2015-04-30-Angler-EK-flash-exploit.swf
File size:  54.0 KB ( 55255 bytes )
MD5 hash:  7d876df50581deb711df9af0029f64e4
Detection ratio:  2 / 57
First submission:  2015-04-29 16:07:35 UTC
VirusTotal link:  https://www.virustotal.com/en/file/cb02bd62e843b45a78e16a5be6ac3bbc1650d1e9446e964ace518a6b7b3e8f54/analysis/

 

MALWARE PAYLOAD:

File name:  2015-04-30-Angler-EK-malware-payload-alpha-crypt.exe
File size:  411.0 KB ( 420864 bytes )
MD5 hash:  1c71d29bede55f34c9b17e24bd6a2a31
Detection ratio:  5 / 57
First submission:  2015-04-30 00:40:49 UTC
VirusTotal link:  https://www.virustotal.com/en/file/7bdc23cc435305da225148b643fc5273a0bf4e227327e15309fe8d5d98c12c20/analysis/
Malwr link:  https://malwr.com/analysis/Y2RkYjc2ZTQzM2Y3NDFkYmE4ZmQzOTZkNTdkZThlOGE/

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.