Remote Downloader ActiveX: Old Exploits, New Malware
ID: 7e436330-f3d7-597a-b998-87732d38ea56
STIX ID: report--7e436330-f3d7-597a-b998-87732d38ea56
Feed Name: Zscaler Security Research Blog
The report analyzes a malicious webpage that embeds at least eight ActiveX exploits (several tied to CVEs from 2006–2009) and attempts to download two malicious payloads and Java applets. The page uses known browser/ActiveX vulnerabilities to achieve remote code execution without user interaction; one payload had only 6/40 antivirus detections and the other 18/40, highlighting detection gaps and the need for defense-in-depth (patching, exploit detection, and payload detection).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
