In The Wild Flash Exploit Analysis – Part 2
ID: bb939eae-9bf0-5a64-897b-5e7c2dedf256
STIX ID: report--bb939eae-9bf0-5a64-897b-5e7c2dedf256
Feed Name: Zscaler Security Research Blog
Technical analysis of an in-the-wild Flash exploit chain: the blog details how heap-sprayed shellcode is XOR-decoded, reveals embedded URLs and strings, and shows the exploit downloading css.exe and multiple payloads from drop sites (e.g., ffxiname.com, 40sys40.cn). The downloaded artifacts include DLLs and executables that are persisted and used to steal web credentials and deliver additional browser-specific exploits; the author recommends updating Flash/AV to mitigate the active threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
