In The Wild Flash Exploit Analysis – Part 1
ID: 4d47b58a-759d-5323-8b37-a29809a053d0
STIX ID: report--4d47b58a-759d-5323-8b37-a29809a053d0
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes a drive-by Flash exploit found at http://www.39sys39.cn/htm/ie.html that uses obfuscated JavaScript and heap spraying to place shellcode at 0x08080808 and trigger CVE-2009-1862, enabling remote code execution; the author validates exploitation by substituting shellcode to launch calc.exe and debugs the crash path in OllyDbg, with a promise to analyze the original payload in a subsequent part.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
