Ongoing Angler Exploit Kit And Bedep Fraud Campaign
ID: 35fb5f92-4d77-5dfe-bc0c-7ac88507cece
STIX ID: report--35fb5f92-4d77-5dfe-bc0c-7ac88507cece
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes a Bedep malware campaign that leveraged the CVE-2015-0311 Flash exploit to install binaries which resolve DGA-generated domains using regway.com nameservers; researchers enumerated ~70+ malicious domains (many resolving to OVH-hosted IPs), multiple ASNs/netblocks, examples of C2 POSTs with base64 payloads, and use of the infrastructure for click-fraud and Reveton ransomware pages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
