Rig Exploit Kit delivers Ransomware
I have added a zipped pcap file for your analysis. The password for the zipped pcap is “infected” all lowercase. PCAP file of the infection traffic: 2020-03-04-Rig-EK-Ransomware-pcap.zip ASSOCIATED...
View ArticleFallout Exploit Kit delivers Raccoon Stealer
I have added a zipped pcap file for your analysis. The password for the zipped pcap is “infected” all lowercase. PCAP file of the infection traffic: 2020-02-24-Fallout-EK-Raccoon-pcap.zip ASSOCIATED...
View ArticleSpelevo Exploit Kit delivers Gozi Trojan
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2020-02-19-Spelevo-EK-gozi-pcap.zip ASSOCIATED...
View ArticleExample traffic of the Underminer Exploit Kit and how it interacts with an...
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2020-02-16-Underminer-EK-pcap.zip ASSOCIATED DOMAINS:...
View ArticleRig Exploit Kit delivers Dridex
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2020-02-15-Rig-EK-Dridex-pcap.zip ASSOCIATED DOMAINS:...
View ArticleRig Exploit Kit delivers Dridex
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2020-01-30-Rig-EK-Dridex.zip ASSOCIATED DOMAINS:...
View ArticlePurple Fox Exploit Kit drops fileless malware
Purple Fox Exploit Kit is known to be a fileless malware distributor. I did not see a payload dropped confirming fileless activity. For a more detailed analysis on Purple Fox, see TrendMicro’s blog –...
View ArticleSpelevo Exploit Kit delivers malware
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2019-12-03-Spelevo-ek-pcap.zip ASSOCIATED DOMAINS:...
View ArticleRig Exploit Kit delivers Bot Ransomware
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2019-11-30-RigEK-pcap.zip ASSOCIATED DOMAINS:...
View ArticleFallout Exploit Kit delivers suspect Remote Access Trojan (RAT)
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2019-11-25-FalloutEK-pcap.zip ASSOCIATED DOMAINS:...
View ArticleThree days of a Smoke Loader infection and follow-up malware
Smoke Loader is a malicious bot application that can be used to load other malware. Smoke Loader has been seen in the wild since at least 2011 and has included a number of different payloads. It is...
View ArticleRig EK delivers Predator the Thief, MedusaHTTP, and Smoke Loader downloader
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2019-11-20-RigEK-pcap.zip ASSOCIATED DOMAINS:...
View ArticleFallout Exploit Kit delivers Raccoon Stealer
NOTE: Some of the base64 powershell is running off the blog page. Using “Reader View” in Browser will show complete poweshell scripts’ The initial redirect was shared in a tweet by @adrian__luca. He...
View ArticleRig Exploit Kit delivers Predator the Thief and Bot Ransomware
Predator the Thief steals passwords from browser and cryptocurrency wallets from infected hosts. A good analysis can be found at Fortinet.com. Bot ransomware has been linked to Dharma ransomware by...
View ArticleQbot Trojan delivered via malspam
[UPDATE] – Thanks to @kafeine for properly identifying the malware as Qbot. Post has been updated to reflect the identification. I have added a zipped pcap file for your analysis. The password for the...
View ArticleRig Exploit Kit drops malware
I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the infection traffic: 2019-08-05-RigEK.zip ASSOCIATED DOMAINS:...
View ArticleLord Exploit Kit delivers Eris ransomware
Lord Exploit Kit discovered by @adrian__luca on 2019-08-01 and shared with the security community. Thank you Adrian and nice find! This exploit appears to be exploiting “Windows VBScript Engine...
View ArticleRig Exploit Kit delivers Bunitu Malware
Thanks to @david_jursa for sharing this information on the Rig EK I have added a zipped pcap file for your analysis. The password for the zipped pcap is infected all lowercase. PCAP file of the...
View ArticleOnline Retailer compromised by four JavaScript Credit Card sniffers
ASSOCIATED DOMAINS: magento-security.org/js/pc-security.js – Credit card JavaScript Sniffer bootstrap-js.com/js/bootstrap.min.js – Credit card JavaScript Sniffer...
View ArticleFrench Designer Clothing Line “A.P.C” compromised by MageCart Credit Card...
NOTE: This blog post was submitted by @MeltX0R, a security researcher. ASSOCIATED DOMAINS: www.apc-us.com – Compromised Website alabamascripts.com – MageCart owned domain serving Malicious JavaScript...
View Article