An Update On Nuclear (Reverse) Engineering
ID: fc819b99-ee24-597d-8fbb-a3f73e345374
STIX ID: report--fc819b99-ee24-597d-8fbb-a3f73e345374
Feed Name: Zscaler Security Research Blog
This analysis details a Nuclear exploit-kit campaign that compromises WordPress sites to serve obfuscated landing pages which probe browser/Flash versions and exploit CVE-2015-5122, CVE-2015-5560 (Flash) and CVE-2014-6332 (IE). Post-exploitation payloads observed include the Fareit infostealer and Troldesh ransomware; the report documents TTPs (iframe injection, obfuscation, DH/XTEA protections), C2-evasion techniques including Tor and blend-in HTTP POSTs, and specific IOCs such as [email protected], [email protected] and a4yhexpmth2ldj3v.onion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
