2015-06-08 - ANGLER EK - MORE CHANGES IN TRAFFIC PATTERNS

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

CHAIN OF EVENTS

ASSOCIATED DOMAINS:

 

FLASH AD REDIRECT:

 

ANGLER EK:

 

POST-INFECTION TRAFFIC:

 

ALERTS

Signature hits from the Emerging Threats and ETPRO rulesets using Sguil on Security Onion (without ET POLICY or ET INFO events):

 

PRELIMINARY MALWARE ANALYSIS

FLASH EXPLOIT:

File name:  2015-06-08-Angler-EK-flash-exploit.swf
File size:  55,364 bytes
MD5 hash:  e1ee52baee1ac7fe876cf6581e669b6c
Detection ratio:  1 / 57
First submission to VirusTotal:  2015-06-08 07:42:59 UTC

 

MALWARE PAYLOAD:

File name:  2015-06-08-Angler-EK-malware-payload.exe
File size:  371,060 bytes
MD5 hash:  d5cd69ad84cc4381275d93c400702f2f
Detection ratio:  1 / 57
First submission to VirusTotal:  2015-06-08 14:03:22 UTC

 

VAWTRAK FOUND ON INFECTED HOST:

File name:  C:\ProgramData\DajaXunuq\PupqUhgo.pmh
File size:  284,582 bytes
MD5 hash:  a0141ac093a4f2bb64e8da3829d4b8a8
Detection ratio:  3 / 57
First submission to VirusTotal:  2015-06-08 14:03:48 UTC
HKEY_CURRENT_USER\Sofware\Microsoft\Windows\CurrentVersion\Run
Value name: DajaXunuq
Type: REG_SZ
Data: regsvr32.exe "C:\ProgramData\DajaXunuq\PupqUhgo.pmh"

 

Click here to return to the main page.