2015-05-14 - NUCLEAR EK DELIVERS RANSOMWARE

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

NUCLEAR EK:

 

POST-INFECTION TRAFFIC:

 

PRELIMINARY MALWARE ANALYSIS

NUCLEAR EK FLASH EXPLOIT:

File name:  2015-05-14-Nuclear-EK-flash-exploit.swf
File size:  18,895 bytes
MD5 hash:  94e60bcae544717cd530b20c644a9d56
Detection ratio:  0 / 57
First submission to VirusTotal:  2015-05-13 18:57:43 UTC

 

RANSOMWARE:

File name:  C:\Users\username\AppData\Local\skhwyva.exe
File size:  518,144 bytes
MD5 hash:  58e1e0b122490dd5bf4a81776772b33c
Detection ratio:  0 / 55
First submission to VirusTotal:  2015-05-14 18:45:06 UTC

 

Click here to return to the main page.