Malvertising: Not all Java from java.com is legitimate
ID: 2bc65ad4-f31c-58ae-be68-e2b0c6ea62ea
STIX ID: report--2bc65ad4-f31c-58ae-be68-e2b0c6ea62ea
Feed Name: Fox-IT blog
Fox-IT observed a malvertising campaign leveraging real-time bidding to inject malicious ads on high-profile websites (e.g., java.com, deviantart.com, tmz.com) that redirected users to the Angler exploit kit which checked for vulnerable Java/Flash/Silverlight and dropped Asprox/Rerdom payloads; the report includes observed exploit domains/ports, passive DNS IPs, fast-flux malware domains, MD5 hashes of encrypted/decrypted payloads, and recommendations (click-to-play, plugin updates, adblockers).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
