[2018-01-25] Seamless->RigEK->Ramnit

January 25, 2018

Overview

Saz file is 2018-01-25_00-01-31.saz

(↓Analysis result using EKFiddle)

Malware

Ramnit

519c9e4bcb32c785f6fadefe2e874975da6425526a0a69259d951e6d328aafff
[Hybrid-Analysis] [VirusTotal]

Traffic-Chain

[Seamless]
http[:]//xn--b1aanbnczd5ie1bf.xn--p1ai/redirect.php
↓
http[:]//treculty-porditely.com/voluum/75499eb6-b2f0-45ea-9fd7-4fb987d432b1
↓
http[:]//redirect.treculty-porditely.com/redirect?target=BASE64aHR0cDovL3huLS04MGFibWk1YWVjZnQueG4tLXAxYWNmL2dhdjIucGhw&ts=1516806002669&hash=YegkBr8zh-UtIwAgBSF_ERYLFsBQJDEaeyLDtjGq4jg&rm=D
↓
[Seamless]
http[:]//xn--80abmi5aecft.xn--p1acf/gav2.php
↓
[RigEK][Landing Page]
http[:]//188.225.74.197/?NDc1NTQy&sVYsKgCTVMmNzDA&vHZjdCWU=bG9jYXRlZA==&FkqxjfcqeIQOp=bG9jYXRlZA==&GnLiqDlTA=YXR0YWNrcw==&adgfg43dgd=xfUpfrQBaQfj3EHVKAZlmY5UU18a9PiqjkXQnBHP0ZSDrBXeMA9N-6KlJLJ_mhj2&ephqCCRINPOz=bWlzc2luZw==&xBrEjPswfV=Y2FwaXRhbA==&BLUfugxZLorwSgH=dW5rbm93bg==&EYBFfgMISqlpkf=YXR0YWNrcw==&fiymUgels=bWlzc2luZw==&UEgtUocZOhk=YXR0YWNrcw==&hfJlRpvhNFnPVsy=bG9jYXRlZA==&NxAtKlB=ZGVub21pbmF0aW9ucw==&bhFgCLECwTUSL=ZGVub21pbmF0aW9ucw==&cVJJtbxX=Y2FwaXRhbA==&lsFEQrLEOlXz=bWlzc2luZw==&CHESOUuqLce=Y2FwaXRhbA==&cbge3sdfsd=w3jQMvXcJxzQFYbGMvjDSKNbNkrWHViPxoqG9MildZiqZGX_k7bDfF-qoVvcCgWR&gHxOmqChKTSNYuE=Y2FwaXRhbA==&OvCNQgpimxGys=dW5rbm93bg==&AlmuBglYfL=bG9jYXRlZA==&MUpUQxZAIQPeY=Y2FwaXRhbA==&DfXYDzqhIfz=ZGVub21pbmF0aW9ucw==
↓
[RigEK][SWF Payload]
http[:]//188.225.74.197/?MTI0OTY5&ngiwOTqMZKlS&LSsdeXplUaECfK=YXR0YWNrcw==&aTaXhGZ=bWlzc2luZw==&TeCjIKT=cmVwb3J0&kJFnvj=dW5rbm93bg==&urZFASubXfsp=Y2FwaXRhbA==&KovACMM=Y2FwaXRhbA==&OxesMyQhbfPrki=dW5rbm93bg==&vsDXmL=ZGVub21pbmF0aW9ucw==&uOoOvDqdYHdDiW=cmVwb3J0&cbge3sdfsd=wn3QMvXcKBXQFYbGKuXDSKBDKU7WGUaVw4-ahMG3YpjNfynz1-zURnL3tASVVFmRrbMdLr&BeKqsyPuJnQnql=ZGVub21pbmF0aW9ucw==&pQKUeg=ZGVub21pbmF0aW9ucw==&NyblywDc=bWlzc2luZw==&sAEtlV=dW5rbm93bg==&JrAQurBnKF=c3Rvcm1lZA==&EpuyvCoI=c3Rvcm1lZA==&OBrlElhXKsH=ZGVub21pbmF0aW9ucw==&adgfg43dgd=YDO1Lk2UfRfwE0z4pYV1oa9qCojRDRyRCZ1ZDR_kSMMApGrMOdELcL2l_3yrcWQIgigECy&IixuGo=Y2FwaXRhbA==&nNQJkzaKqvcSJN=bWlzc2luZw==&UDCUieaSmhTg=YXR0YWNrcw==&FaqMTWn=Y2FwaXRhbA==