logo

Java Drive By Download Attack

ID: 54c00e0e-ca05-5615-a1df-21c2c998d872

STIX ID: report--54c00e0e-ca05-5615-a1df-21c2c998d872

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This blog details a drive-by download attack delivered via a Java applet on http://www.nicholaspettas.com/ that prompts the user to run a Client.jar; the applet downloads and executes server_crypt.exe from Dropbox. The post includes HTML/source screenshots, Wireshark captures, decompiled Java showing execution of the downloaded EXE, and VirusTotal/ThreatExpert detections labeling the components as Trojan downloader/malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.