Sundown Chronicles - Exploit Kit's Evolution
ID: 3e22d89e-4735-5582-b720-70f693a258e7
STIX ID: report--3e22d89e-4735-5582-b720-70f693a258e7
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes Sundown exploit kit activity (June–July 2016), documenting iterative changes to landing pages and payload delivery mechanisms, the delivery of NetWire RAT and Kasidet, exploitation techniques including Flash shellcode and base64-inflated JavaScript, and enumerates IOCs (file hashes, domains, hosting IPs); it concludes Sundown is less sophisticated than top EKs but actively evolving and poses an ongoing malware-delivery risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
