CookieBomb Still Dropping Malicious Content
ID: e95ea82f-9228-5c45-b458-8fd11ab2253e
STIX ID: report--e95ea82f-9228-5c45-b458-8fd11ab2253e
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes the "Cookiebomb" drive-by infection campaign in which obfuscated JavaScript injected into legitimate websites creates cookies and hidden 1px iFrames, fingerprints browser plugin versions, performs multi-stage redirections to evade detection, and ultimately drops a trojanous executable; the report provides deobfuscated code, attack URLs, Fiddler session evidence, and a long list of compromised sites while noting low AV detection (7/45).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
