Tag Archives: Malspam E-mail Leads to Ransomware Cerber/Zerber Infection TRAFFIC SAMPLE

Malspam E-mail Leads to Ransomware Cerber/Zerber Infection TRAFFIC SAMPLE

  Example of files that were encrypted and protected:   The domain name ftoxmpdipwobp4qy.joa688.top was NX and not required for the purchase process. 2016-12-16 01:29:05.256362 IP 192.168.1.102.50104 > 72.167.232.152.80: Flags [P.], seq 0:303, ack 1, win 256, length 303: HTTP: GET //up1/1/4fv3b5.exe HTTP/1.1 E..W..@……..fH……P.n……P…….GET //up1/1/4fv3b5.exe HTTP/1.1 Accept: application/x-shockwave-flash, image/gif, image/jpeg, image/pjpeg, */* Accept-Language: en-us User-Agent: Mozilla/4.0… Read More »

Share Button