logo

In The Wild Flash Exploit Analysis – Part 1

ID: 4d47b58a-759d-5323-8b37-a29809a053d0

STIX ID: report--4d47b58a-759d-5323-8b37-a29809a053d0

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes a drive-by Flash exploit found at http://www.39sys39.cn/htm/ie.html that uses obfuscated JavaScript and heap spraying to place shellcode at 0x08080808 and trigger CVE-2009-1862, enabling remote code execution; the author validates exploitation by substituting shellcode to launch calc.exe and debugs the crash path in OllyDbg, with a promise to analyze the original payload in a subsequent part.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.