2017-03-14 KOVTER INFECTION WITH NEMUCOD RANSOMWARE

NOTICE:

ASSOCIATED FILES:

 

NOTES:


Shown above:  Desktop of the infected Windows host.

 

EMAIL


Shown above:  Screen shot of the email.

 

EMAIL HEADERS:

 


Shown above:  Attached zip archive from the email.

 


Shown above:  Extracted .js file from the zip archive.

 

TRAFFIC


Shown above:  Traffic from the infection filtered in Wireshark.

 

TRAFFIC FROM AN INFECTION:

 


Shown above:  Some alerts on the traffic from the Emerging Threats and ETPRO rulesets using Sguil on Security Onion.

 

FILE HASHES

SOME FILES FROM THE ZIP ARCHIVE:

Artifacts on the infected host:

 

Click here to return to the main page.