Posts

Showing posts with the label dive

A dive into the wake of the RIG EK leak

Image
A dive into the wake of the RIG EK leak Not long ago it became clear that parts of the exploit kit RIG was leaked, including both source code (admin) and database. @MalwareTechBlog wrote a post which summarizes the story behind the leak. As the database included actual traffic and details from where the traffic was coming from it was possible to do some digging into in the origins of the redirects. I settled on one of the referers found in the database as it was still active; oxprxt.tk which at the time of writing has been taken offline (domain does not resolve anymore). However, I will cover what was available and what data that has been collected during the analysis. The flow which is associated with the referer was "51" and well, its not that impressive in terms of traffic volume, however, since more than 0 exploits launched, it gives the possibility of an infection: Flow 51 This particular flow is associated with a user called "GenocideUID1971983" which can be...