Chinese Govt. Website Compromised, Leads To Angler
ID: 9da454b3-4243-5308-817e-d9b500c480b8
STIX ID: report--9da454b3-4243-5308-817e-d9b500c480b8
Feed Name: Zscaler Security Research Blog
ThreatLabZ observed a non-targeted compromise of the Chuxiong Archives (www.cxda.gov.cn) that injected obfuscated code redirecting Internet Explorer users to Angler Exploit Kit landing pages. The Angler kit exploited Flash (CVE-2015-7645) to deliver a CryptoWall 3.0 variant (crypt13), with analysis showing updated landing-page/SWF structures, multiple landing domains and a larger set of C2 servers; the site was remediated within 24 hours. The report provides SWF and landing page analysis and indicators of compromise for detection and tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
