Defaced Websites Leading To Dokta Chef Exploit Kit
ID: 3519be3b-b785-5fae-8528-f8fe8add60a7
STIX ID: report--3519be3b-b785-5fae-8528-f8fe8add60a7
Feed Name: Zscaler Security Research Blog
**Executive Summary:** Multiple websites were defaced by a group claiming to be AnonGhostTeam and were found hosting a highly obfuscated "lulz.htm" page that redirected visitors to the Dokta Chef exploit kit, which attempted to deliver a remote code execution exploit for CVE-2014-6332 targeting 32-bit Internet Explorer on Windows; Zscaler observed numerous compromised sites, documented indicators and protections have been deployed, and the final payload was not reachable at the time of analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
