Analysis of malicious advertisements on telegraaf.nl
ID: 09f8bee9-670a-55d8-a466-8b40f69d2b27
STIX ID: report--09f8bee9-670a-55d8-a466-8b40f69d2b27
Feed Name: Fox-IT blog
Threat Score
Fox-IT detected malvertising on telegraaf.nl that redirected users to the "FlimKit" exploit kit which leveraged Java vulnerabilities (CVE-2012-1723, CVE-2013-2423) to deliver winlocker binaries; the report provides MD5 hashes, malicious domains (including DGA-generated .nl domains), IP addresses, HTTP request traces and cleanup instructions for infected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
