Neutrino Campaign Leveraging WordPress, Flash For CryptoWall
ID: 962b574f-327f-5295-966b-d505e6102b88
STIX ID: report--962b574f-327f-5295-966b-d505e6102b88
Feed Name: Zscaler Security Research Blog
This ThreatLabZ write-up describes an active Neutrino Exploit Kit campaign that compromises over 2,600 WordPress sites (and >4,200 pages) running version 4.2 and lower to inject iframes which load Neutrino landing pages and a SWF-based exploit chain; successful exploitation downloads and decrypts a binary that beacons and deploys CryptoWall 3.0 ransomware. The report analyzes landing page and SWF structure (including obfuscation and embedded RC4 blobs), notes poor detection rates, provides campaign infrastructure details (e.g., primary IP 185.44.105.7, domains across .xyz/.ga/.gq/.ml, WHOIS samples), and publishes indicators and a domain dump for tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
