Post mortem report on the sinowal/nu.nl incident
ID: 7d2f78b1-6a6d-5c3d-b0e7-5d0da1b69675
STIX ID: report--7d2f78b1-6a6d-5c3d-b0e7-5d0da1b69675
Feed Name: Fox-IT blog
Threat Score
Executive summary: A malvertising campaign on the Dutch site nu.nl (14 Mar 2012) injected obfuscated JavaScript that redirected visitors to Nuclear Pack exploit kit pages, exploiting Java vulnerabilities to deliver SmokeLoader downloader and Sinowal/Mebroot components; the report provides IoCs (domains, IPs, URLs, filenames), technical analysis of persistence/evasion techniques, and containment actions taken (domain takedown, coordination with Spamhaus and host provider).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
