Malicious JavaScript targets 3 Old Vulnerabilities
ID: 083d36ba-ea8f-5545-afe8-05b8ee09a7d3
STIX ID: report--083d36ba-ea8f-5545-afe8-05b8ee09a7d3
Feed Name: Zscaler Security Research Blog
Threat Score
The report demonstrates a PDF exploitation technique where attackers split malicious JavaScript across objects and encode each part with different filters (ASCIIHexDecode and ASCII85Decode) to evade AV detection; the decoded payload targets three legacy PDF vulnerabilities (CVE-2007-5659, CVE-2008-2992, CVE-2009-0927), a live sample is shown with low antivirus detection rates, and the author recommends defense-in-depth measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
