PDF Exploits Targeted Through Blackhole Exploit Kits.
ID: 638f9362-e793-5bdd-b451-74a7cf032bc4
STIX ID: report--638f9362-e793-5bdd-b451-74a7cf032bc4
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes Blackhole exploit kit PDF-based attacks that leverage an Adobe Reader getIcon() buffer overflow (CVE-2009-0927) to achieve code execution. It presents de-obfuscated JavaScript from the malicious PDFs, lists observed payload URLs (for example: http://flightpub.net/l/content/ap1.php?f=97d19::182b5 and variants), and provides example Snort signatures and mitigation advice (patching/updating Adobe Reader).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
