CVE-2010-0806 Exploit In The Wild
ID: 1767e608-05aa-5e4a-a5bd-96f59d5cc060
STIX ID: report--1767e608-05aa-5e4a-a5bd-96f59d5cc060
Feed Name: Zscaler Security Research Blog
This report documents active exploitation of Internet Explorer vulnerability CVE-2010-0806: obfuscated JavaScript hosted on cn.cnsa56.info (and a supporting k.js) decodes shellcode which downloads a likely-encrypted payload (v.vkjk6.info/w/win.exe). The payload showed no antivirus detections at the time, the exploit and domains were analyzed with WHOIS/registration details provided, and the author notes probable Chinese-language attribution based on registration/email and variable names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
