Unknown Adultfriendfinder Malware Loads Click Fraud Adware PCAP Traffic Sample

2014-12-31 21:42:01.338041 IP 192.168.138.158.49167 > 91.109.247.12.80: Flags [S], seq 2496731022, win 8192, options [mss 1460,nop,wscale 2,nop,nop,sackOK], length 0 E..4..@…[q….[m…..P………. .D…………… 2014-12-31 21:42:01.525412 IP 91.109.247.12.80 > 192.168.138.158.49167: Flags [S.], seq 2472158945, ack 2496731023, win 64240, options [mss 1460], length 0 E..,.]……[m…….P…Z&…..`….h…….. 2014-12-31 21:42:01.525564 IP 192.168.138.158.49167 > 91.109.247.12.80: Flags [.], ack 1, win 64240, length 0 E..(..@…[|….[m…..P…..Z&.P….%……..… Read More »

E-mail Spam Upatre Trojan Downloader Loads Dyre SSL/443 Trojan and Pony Downloader Malware PCAP Traffic Sample

2015-01-27 14:21:25.061276 IP 192.168.221.134.49500 > 202.153.35.133.15175: Flags [S], seq 1519016217, win 8192, options [mss 1460,nop,wscale 2,nop,nop,sackOK], length 0 E..4.G@…_/……#..\;GZ.Y……. …………….. 2015-01-27 14:21:25.559710 IP 202.153.35.133.15175 > 192.168.221.134.49500: Flags [S.], seq 3577950926, ack 1519016218, win 64240, options [mss 1460], length 0 E..,……….#…..;G.\.C2.Z.Y.`…X}…….. 2015-01-27 14:21:25.560035 IP 192.168.221.134.49500 > 202.153.35.133.15175: Flags [.], ack 1, win 64240, length 0 E..(.H@…_:……#..\;GZ.Y..C2.P…p:……..… Read More »

CryptoWall Ransomware ip-addr.es Malware PCAP Traffic Sample Analysis

2015-02-06 17:01:26.933605 IP 192.168.221.134.56756 > 192.168.221.2.53: 47786+ A? ip-addr.es. (28) E..8……………….5.$wa………….ip-addr.es….. 2015-02-06 17:01:27.028356 IP 192.168.221.2.53 > 192.168.221.134.56756: 47786 1/0/0 A 188.165.164.184 (44) E..H!…… ………5…4.I………….ip-addr.es………………… 2015-02-06 17:01:27.029865 IP 192.168.221.134.49316 > 188.165.164.184.80: Flags [S], seq 2283557266, win 8192, options [mss 1460,nop,wscale 2,nop,nop,sackOK], length 0 E..4..@…./………..P..Q……. …………….. 2015-02-06 17:01:27.158132 IP 188.165.164.184.80 > 192.168.221.134.49316: Flags [S.], seq 351522798, ack… Read More »