IE 0-Day On GOV.CN
ID: 1b078f6e-c63a-5641-b2ef-2f5c0a071e67
STIX ID: report--1b078f6e-c63a-5641-b2ef-2f5c0a071e67
Feed Name: Zscaler Security Research Blog
A report describes multiple Chinese government (.gov.cn) web pages actively hosting an Internet Explorer zero-day exploit (CVE-2010-0249) that loads shellcode via ev1/ev2 JavaScript routines to download a payload named v.exe, identified as a Hupigon backdoor. The analysis includes screenshots of the exploit code, VirusTotal detection (12/41), AV attribution to Hupigon (capabilities include webcam access, DDoS, rootkit, keylogging and data exfiltration), and lists several affected government domains, warning users (especially IE6 users) to upgrade or avoid IE.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
