2015-11-22 - BIZCN GATE ACTOR NUCLEAR EK FROM 5.175.194[.]135 - 439520.13406.DUCO-OR[.]XYZ
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSSOCIATED FILES:
- 2015-11-22-BizCN-gate-actor-Nuclear-EK-traffic.pcap.zip 287.5 kB (287,471 bytes)
- 2015-11-22-BizCN-gate-actor-Nuclear-EK-malware-and-artifacts.zip 219.2 kB (219,189 bytes)
IMAGES
Shown above: Pcap of the traffic filtered in Wireshark.
Shown above: Injected script in page from the comrpomised website.
Shown above: Malware retrieved from the infected host.
Click here to return to the main page.