Help Center URL Validation Vulnerability Campaign
ID: 4b530faa-18dc-5f69-919d-92ecdf93005f
STIX ID: report--4b530faa-18dc-5f69-919d-92ecdf93005f
Feed Name: Zscaler Security Research Blog
Threat Score
The report documents an active web-exploit campaign using dyndns-hosted domains and compromised websites to deliver Windows executables and Java .jar payloads. The dropper uses Windows Script Host (cscript) to assemble a .js downloader that fetches an executable (bonjour.exe) and kills processes matching "help", while associated network indicators and ThreatExpert callbacks point to additional infrastructure and piecemeal payload delivery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
