2015-11-19 - BIZCN GATE ACTOR NUCLEAR EK FROM 5.231.54[.]59 - 16953.FALMUEMB[.]XYZ
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSSOCIATED FILES:
- 2015-11-19-BizCN-gate-actor-Nuclear-EK-traffic.pcap.zip 467.4 kB (467,446 bytes)
- 2015-11-19-BizCN-gate-actor-Nuclear-EK-malware-and-artifacts.zip 428.7 kB (428,719 bytes)
IMAGES
Shown above: Desktop after the CryptoWall 3.0 ransomware infection.
Shown above: Checking the decrypt instructions after the CryptoWall 3.0 ransomware infection.
Shown above: Some of the artifacts left behind after the CryptoWall 3.0 ransomware infection.
Shown above: Pcap of the infection traffic filtered in Wireshark.
Shown above: Malware retrieved from the infected host.
Shown above: Malicious script in page from compromised website.
Shown above: Examples of the gate domains on 46.172.83[.]0/24.
Click here to return to the main page.