CVE-2012-1889 Is Still Alive!
ID: 4cbd23a6-1fef-5302-b797-753fd976e2c5
STIX ID: report--4cbd23a6-1fef-5302-b797-753fd976e2c5
Feed Name: Zscaler Security Research Blog
Zscaler identified a malicious Chinese website (http://wm.17wan.info:9999/...) that exploits CVE-2012-1889 via highly obfuscated JavaScript which performs heap-spray and decodes shellcode to achieve remote code execution in Internet Explorer; the site crashes IE, attempts to evade AV through obfuscation, drops a malicious RAR and contacts external domains (js.users.51.la, web1.51.la:82). Although the vulnerability is from 2012, the report shows it is still being actively exploited against online gamers and includes decoded script analysis and observed HTTP transactions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
