Probing Into The Flash Zero Day Exploit (CVE-2014-0502)
ID: ada7a0db-3001-5fc8-aa13-867210d1b1fc
STIX ID: report--ada7a0db-3001-5fc8-aa13-867210d1b1fc
Feed Name: Zscaler Security Research Blog
This report analyzes an active in-the-wild exploit chain targeting an Adobe Flash zero-day (CVE-2014-0502): an encrypted SWF uses ActionScript to request a GIF containing ROP shellcode which, after successful exploitation, executes code that downloads and drops a Remote Access Trojan (update.exe) into the /temp folder. The analysis documents exploit staging (DoSWF encryption, OS/language checks, cookie gating 'XPT2013111'), shellcode behavior (LoadLibraryA, VirtualProtect, InternetOpenUrlA), and provides indicators and sandbox confirmation of the dropped malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
