FlimKit Coughs Up More Malvertising
ID: 778f2da3-68f2-53c9-930e-9fdda1663518
STIX ID: report--778f2da3-68f2-53c9-930e-9fdda1663518
Feed Name: Zscaler Security Research Blog
FlimKit is an exploit kit distributed via malvertising/popunder ads that exploits Java vulnerabilities (notably CVE-2013-2423) to drop JAR files which lead to malicious executables—typically ZBOT variants. The report lists newly observed drop domains (e.g., 9euei.info, kvmhja.info, sdjeu7.info, adiwep.info, d0e9ue.info, idueya.info, sdioep.info, sieod.info) and ad services (yieldmanager.net, smxchange.com, glispa.com) that redirected users to the exploit kit, indicating an active malvertising campaign and providing IoCs and TTPs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
