2016-08-16 - PSEUDO-DARKLEECH GOES FROM NEUTRINO EK TO RIG EK THEN BACK TO NEUTRINO

NOTICE:

ASSOCIATED FILES:

  • 2016-08-16-pseudoDarkleech-Neutrino-EK-sends-CrypMIC-after-blenheim-lodge_com.pcap   (537,339 bytes)
  • 2016-08-16-pseudoDarkleech-Neutrino-EK-sends-CrypMIC-after-convoyproperty_com.pcap   (443,414 bytes)
  • 2016-08-16-pseudoDarkleech-Rig-EK-after-blenheim-lodge_com.pcap   (730,082 bytes)
  • 2016-08-16-page-from-blenheim-lodge_com-with-injected-script-pointing-to-Neutrino-EK.txt   (99,574 bytes)
  • 2016-08-16-page-from-blenheim-lodge_com-with-injected-script-pointing-to-Rig-EK.txt   (99,712 bytes)
  • 2016-08-16-page-from-convoyproperty_com-with-injected-script-pointing-to-Neutrino-EK.txt   (98,098 bytes)
  • 2016-08-16-pseudoDarkleech-CrypMIC-decrypt-instructions.HTML   (238,182 bytes)
  • 2016-08-16-pseudoDarkleech-CrypMIC-decrypt-instructions.JPG   (228,351 bytes)
  • 2016-08-16-pseudoDarkleech-CrypMIC-decrypt-instructions.TXT   (1,654 bytes)
  • 2016-08-16-pseudoDarkleech-Neutrino-EK-flash-exploit-after-blenheim-lodge_com.swf   (80,112 bytes)
  • 2016-08-16-pseudoDarkleech-Neutrino-EK-landing-page-after-blenheim-lodge_com.txt   (2,354 bytes)
  • 2016-08-16-pseudoDarkleech-Neutrino-EK-landing-page-after-convoyproperty_com.txt   (2,346 bytes)
  • 2016-08-16-pseudoDarkleech-Neutrino-EK-payload-CrypMIC-after-convoyproperty_com.dll   (69,632 bytes)
  • 2016-08-16-pseudoDarkleech-Neutrino-EK-payload-CrypMIC-after-lenheim-lodge_com.dll   (69,632 bytes)
  • 2016-08-16-pseudoDarkleech-Rig-EK-flash-exploit-after-blenheim-lodge_com.swf   (45,960 bytes)
  • 2016-08-16-pseudoDarkleech-Rig-EK-landing-page-after-blenheim-lodge_com.txt   (5,086 bytes)
  • 2016-08-16-pseudoDarkleech-Rig-EK-payload-after-lenheim-lodge_com.exe   (505,344 bytes)

 

NOTES:

 


Shown above:  Flowchart for recent pseudoDarkleech-based infection traffic I've seen.

 

TRAFFIC


Shown above:  Injected script from the pseudoDarkleech campaign in page from a compromised site pointed to Rig EK on 2016-08-15 at 21:25 EDT.

 


Shown above:  Injected script from the pseudoDarkleech campaign in the same compromised site pointed to Neutrino EK on 2016-08-16 at 10:28 EDT.

 


Shown above:  Traffic from the 2016-08-15 infection filtered in Wireshark.   Wireshark filter: http.request

 


Shown above:  Traffic from the 2016-08-16 infection filtered in Wireshark.   Wireshark filter: http.request or (!(tcp.port eq 80) and tcp.flags eq 0x0002)

 

ASSOCIATED DOMAINS:

DOMAINS FROM THE CRYPMIC DECRYPT INSTRUCTIONS:

NOTE: The above 2 domains from the decrypt instructions are the same ones I've seen from CrypMIC since 2016-07-26.

 

FILE HASHES

FLASH EXPLOITS:

 

PAYLOADs:

 

IMAGES


Shown above:  Injected script from the pseudoDarkleech campaign in page from another compromised site on 2016-08-16 pointing to Neutrino EK.

 


Shown above:  Traffic from the other 2016-08-16 pseudoDarkleech Neutrino EK pcap filtered in Wireshark.

 


Shown above:  Desktop of an infected Windows host on 2016-08-16 after rebooting.

 

Click here to return to the main page.