2015-11-21 - BIZCN GATE ACTOR NUCLEAR EK FROM 5.175.185[.]20 - 48637930475.KUPUTSTER[.]XYZ

NOTICE:

ASSSOCIATED FILES:

 

IMAGES


Shown above:  Pcap of the traffic filtered in Wireshark.


Shown above:  Injected script in page from comromised website.


Shown above:  BizCN-registered gate returns javascript.


Shown above:  Full javascript returned from the BizCN-registered gate.


Shown above:  CryptoWall ransomware retrieved from the infected host.


Shown above:  Artifacts left behind after the CryptoWall ransomware infection.


Shown above:  Desktop of the infected host after the CryptoWall ransomware infection.


Shown above:  User checking decrypt instructions for the ransom payment info.

 

Click here to return to the main page.