Expack Continues Exploiting Java Vulnerability
ID: ab37a295-0810-5b40-9a77-3a38e085ac3c
STIX ID: report--ab37a295-0810-5b40-9a77-3a38e085ac3c
Feed Name: Zscaler Security Research Blog
Threat Score
This report examines an exploit kit observed at 174.142.240.91 that exploits CVE-2012-1723 in Java to load an obfuscated applet and download malicious JARs (MD5s provided), leading to a Trojan that communicates with a C2 and retrieves a ZeroAccess-like rootkit (6.exe). The write-up includes IOCs (IP, URLs, MD5 hashes), discusses the exploitation chain and obfuscation, and advises patching or disabling browser Java to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
