2015-06-05 - ANGLER EK FROM 209.133.200[.]228 SENDS BEDEP AND NECURS

NOTICE:

ASSOCIATED FILES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

REDIRECT/GATE:

 

ANGLER EK:

 

POST-INFECTION TRAFFIC:

 

MALWARE

MALWARE FOUND ON THE INFECTED HOST:

 

IMAGES

Edited screenshot of Wireshark showing the traffic:

 

Signature hits from the Emerging Threats and ETPRO rulesets using Sguil on Security Onion (without ET POLICY or ET INFO events):

 

Click here to return to the main page.