Say hello to Bottle Exploit Kit targeting Japan
ID: 4cd75da2-f7a8-54b5-b4a4-d8ae951790b8
STIX ID: report--4cd75da2-f7a8-54b5-b4a4-d8ae951790b8
Feed Name: Nao_Sec
This report documents Bottle Exploit Kit, a malvertising-driven drive-by campaign targeting Japanese users that fingerprints for Japanese-language Internet Explorer and delivers either VBS (CVE-2018-8174) or SWF (CVE-2018-15982) exploits to run shellcode. The payload likely functions as a stealer, downloads auxiliary tools (e.g., unzip, Tor), persists as svchost.exe in %TEMP%, and communicates with onion C2 endpoints. Detailed TTPs and comprehensive IoCs (domains, URLs, file paths, and hashes) are provided to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
