Malvertising Leading To Flash Zero Day Via Angler EK
ID: 8ca30f4a-dea8-5c48-9854-df7d43bb1ea0
STIX ID: report--8ca30f4a-dea8-5c48-9854-df7d43bb1ea0
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ observed a malvertising campaign directing users to Angler Exploit Kit pages that exploited a zero-day Adobe Flash vulnerability (active in early 2015) to silently install a 64-bit Bedep Trojan; the payload performs AdFraud/ClickFraud, uses incremental XOR obfuscation, a DGA for C2, and establishes persistence via copied DLLs and COM CLSID registry entries (MD5 EFB584DEA6CBC03765487633BD5A5920).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
