2016-05-10 - TUESDAY MALWARE HUNT - CERBER RANSOMWARE, LOCKY RANSOMWARE, AND MALWARE FROM BRAZIL EMAIL

NOTICE:

ASSOCIATED FILE:

 

EMAILS AND ATTACHMENTS


Shown above:  Data from the .csv spreadsheet on 8 malicious emails from today.

 


Shown above:  Data from the .csv spreadsheet on 8 attachments from today's emails.

 


Shown above:  Email pushing Locky ransomware example 1 of 2.

 


Shown above:  Email pushing Locky ransomware example 2 of 2.

 


Shown above:  Email pushing Cerber ransomware example.

 


Shown above:  Brazil email example.

 

TRAFFIC


Shown above:  Traffic from executing one of the extracted .hta files, filtered in Wireshark.

 

ASSOCIATED DOMAINS:

HTTP REQUESTS FOR LOCKY RANSOMWARE FROM ONE OF THE .HTA FILES:

HTTP REQUESTS FOR LOCKY RANSOMWARE FROM THE .JS FILES:

POST-INFECTION CALLBACK FROM THE LOCKY RANSOMWARE INFECTIONS:

HTTP REQUEST FOR CERBER RANSOMWARE FROM THE .DOT FILE:

HTTP REQUESTS FROM THE BRAZIL EMAIL:

 

ZIP ARCHIVE CONTENTS

 

Click here to return to the main page.