2015-11-19 - BIZCN GATE ACTOR NUCLEAR EK FROM 5.231.54[.]59 - 16953.FALMUEMB[.]XYZ

NOTICE:

ASSSOCIATED FILES:

 

IMAGES


Shown above:  Desktop after the CryptoWall 3.0 ransomware infection.


Shown above:  Checking the decrypt instructions after the CryptoWall 3.0 ransomware infection.


Shown above:  Some of the artifacts left behind after the CryptoWall 3.0 ransomware infection.


Shown above:  Pcap of the infection traffic filtered in Wireshark.


Shown above:  Malware retrieved from the infected host.


Shown above:  Malicious script in page from compromised website.


Shown above:  Examples of the gate domains on 46.172.83[.]0/24.

 

Click here to return to the main page.