Quantcast
Channel: Noise » exploit kit
Viewing all articles
Browse latest Browse all 18

SANS Internet Storm Center, InfoCON: green: Another example of Angler exploit kit pushing CryptoWall 3.0, (Thu, Jul 2nd)

$
0
0

Introduction

Angler exploit kit (EK) has been evolving quite a bit lately. Recently, this EK hasbeen altering its URL patterns on a near-daily basis. Thechanges accumulate, and you might not recognize current traffic generated byAngler. Aftertwo weeks of vacation, I almost didnt recognize it. This diary provides twotraffic examples of Angler EK as we enter July 2015.

Angler EKstill pushing a lot ofCryptoWall 3.0

Angler pushes different payloads, but were still seeinga lot ofCryptoWall 3.0 from this EK. We first noticed CryptoWall 3.0 from Anglernear the end of May 2015 [1], and weve seen a great dealof itsince then[2]. The CryptoWall 3.0sample for todays diary used1LY58fiaAYFKgev67TN1UJtRveJh81D2dU as a bitcoin">xamples

Traffic from Tuesday, 2015-07-01 shows Angler EKfrom 148.251.167.57 and">148.251.167.107 at different times during the day. ">The people at Emerging Threats do a good job of keeping their Snort-based signatures up-to-date through their ETOpen and Proofpoint ET Pro rulesets. Below is an image of events fromthe infection traffic I saw using Suricata on" />

Preliminary malware analysis

Sample of a CryptoWall 3.0 malware payload delivered by Angler EK on 2015-07-01:

Final words

Pcap files of the 2015-07-01 infection traffic are available at:

A zip file of the associated malware is available at:

The zip file is password-protected with the standard password. If you dont know it, email admin@malware-traffic-analysis.net and ask.

---
Brad Duncan
ISC Handler and Security Researcher at Rackspace
Blog: www.malware-traffic-analysis.net - Twitter: @malware_traffic

References:

[1] https://isc.sans.edu/diary/Angler+exploit+kit+pushing+CryptoWall+30/19737
[2] https://isc.sans.edu/diary/Increase+in+CryptoWall+30+from+malicious+spam+and+Angler+exploit+kit/19785

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Viewing all articles
Browse latest Browse all 18

Latest Images

Trending Articles





Latest Images