2017-04-06 - "BLANK SLATE" CAMPAIGN STILL PUSHING CERBER RANSOMWARE, STILL USING FAKE CHROME PAGE

NOTICE:

ASSOCIATED FILES:

 

BACKGROUND:

OTHER NOTES:

 

FAKE CHROME PAGE


Shown above:  Screen shot from the fake Microsoft email.

 


Shown above:  Letting the fake Chrome page send a fake Chrome update as a zip archive.

 


Shown above:  Zip acrhive sent by the fake Chrome page contains (Cerber) ransomware.

 

TRAFFIC

HTTP TRAFFIC FOR THE RANSOMWARE FOR THE PAST FEW DAYS:

RANSOMWARE DOWNLOAD FROM FAKE CHROME INSTALL PAGE ON THURSDAY 2017-04-06:

 

MALWARE

SHA256 HASHES FOR CERBER RANSOMWARE SAMPLES:

 

IMAGES


Shown above:  Desktop of an infected Windows host.  Note the dollar signs used for the letter S.

 

Click here to return to the main page.