2015-05-14 - NUCLEAR EK FROM 109.234.37[.]12 - SENDS NECURS

NOTICE:

ASSOCIATED FILES:

 

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

REDIRECT/GATE:

 

NUCLEAR EK:

 

POST-INFECTION HTTP TRAFFIC:

 

POST-INFECTION DNS QUERIES:

 

POST-INFECTION UDP TRAFFIC:

 

PRELIMINARY MALWARE ANALYSIS

MALWARE PAYLOAD:

File name:  2015-05-14-Nuclear-EK-malware-payload.exe
File size:  115,200 bytes
MD5 hash:  0db7cbfc1220b22b47eddd945f99940c
Detection ratio:  10 / 57
First submission to VirusTotal:  2015-05-14 21:27:25 UTC

 

Click here to return to the main page.