logo

Malvertising: Not all Java from java.com is legitimate

ID: 2bc65ad4-f31c-58ae-be68-e2b0c6ea62ea

STIX ID: report--2bc65ad4-f31c-58ae-be68-e2b0c6ea62ea

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2014-08-27

Date Updated: 2026-04-27

...
...

Fox-IT observed a malvertising campaign leveraging real-time bidding to inject malicious ads on high-profile websites (e.g., java.com, deviantart.com, tmz.com) that redirected users to the Angler exploit kit which checked for vulnerable Java/Flash/Silverlight and dropped Asprox/Rerdom payloads; the report includes observed exploit domains/ports, passive DNS IPs, fast-flux malware domains, MD5 hashes of encrypted/decrypted payloads, and recommendations (click-to-play, plugin updates, adblockers).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.