2016-05-24 - TUESDAY MALWARE HUNT

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

  • 1st wave:   .wsf files   -   Subject: Re:
  • 2d wave:   .js files that retrieved Locky ransomware sample 1   -   Subject: SAFARI LPO [MAL] [random characters]
  • 3d wave:   .js files that retrieved Locky ransomware sample 2   -   Subject: We Have Received Your Payment - Thank You (#[random characters])
  • 4th wave:   Word documents with macros that downloaded Dridex   -   Subject: Account Compromised
  • 5th wave:   .js files that retrieved Locky ransomware sample 1   -   Fake HP Scanjet messages

 

EMAILS AND ATTACHMENTS


Shown above:  Data from the .csv spreadsheet on 20 email examples from Tuesday 2016-05-24.

 


Shown above:  Data from the .csv spreadsheet on 20 attachments from email samples on Tuesday 2016-05-24.

 

TRAFFIC


Shown above:  Example of traffic from zip attachments containing .wsf files.

 

TRAFFIC GENERATED BY THE .WSF FILES FROM ZIP ATTACHMENTS IN THE EMAILS:

 


Shown above:  Example of traffic from zip attachments containing .js files for first sample of Locky ransomware.

 

TRAFFIC GENERATED BY THE .JS FILES FROM ZIP ATTACHMENTS IN THE EMAILS FOR FIRST LOCKY RANSOMWARE SAMPLE:

POST-INFECTION TRAFFIC FROM THE FIRST LOCKY RANSOMWARE SAMPLE:

 


Shown above:  Example of traffic from zip attachments containing .js files for second sample of Locky ransomware.

 

TRAFFIC GENERATED BY THE .JS FILES FROM ZIP ATTACHMENTS IN THE EMAILS FOR SECOND LOCKY RANSOMWARE SAMPLE:

POST-INFECTION TRAFFIC FROM THE SECOND LOCKY RANSOMWARE SAMPLE:

 


Shown above:  Example of traffic from zip attachments containing the .doc files for Dridex.

 

INITIAL HTTPS TRAFFIC AFTER ENABLING MACROS ON FROM ZIP FILES CONTAINING WORD DOCS FOR DRIDEX:

  • countryName = MU
  • localityName = Port Louis
  • organizationName = Beffls Ffjouc SCA
  • commonName = buke223.brcherinliemas[.]team

ENCRYPTED TRAFFIC OR ATTEMPTED CONNECTIONS FROM THE DRIDEX INFECTIONS:

 

IMAGES


Shown above:  SSL certificate info from one of the Dridex pcaps.

 

ZIP ARCHIVE CONTENTS

 

Click here to return to the main page.