Blackhole Exploit Kit Continues It’s Dominance
ID: ca803762-4c24-5072-be18-9cea968e061a
STIX ID: report--ca803762-4c24-5072-be18-9cea968e061a
Feed Name: Zscaler Security Research Blog
Threat Score
This report describes an investigation of malicious iframe injections on legitimate webpages used to deliver the Blackhole exploit kit. The author documents heavy obfuscation in HTML body tags, demonstrates manual de-obfuscation to reveal malicious /index.php?tp= URLs, shows the exploit payloads that target older vulnerabilities and download binaries, and notes low antivirus detection — indicating an active drive-by exploit campaign employing evasive TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
