Quantcast
Channel: Malware don't need Coffee
Viewing all articles
Browse latest Browse all 185

CVE-2013-7331 and Exploit Kits

$
0
0


Thanks to EKWatcher and his decoding skills saving me a lot of time.

As we can see more and more of those "XMLDOM" checks in  exploit kits i decided to write here some of the checks spotted. This is a fast moving area and it will be hard to keep up to date with this, but this may give an idea of how it's being used.

Angler EK:

http://pastebin.com/EAKZk43e  2014-10-01
Previously :
http://pastebin.com/pzx2xPDJ 2014-08-23


Astrum EK :






http://pastebin.com/PfAjuvPR 2014-09-06

Nuclear Pack :







Read more:
Attackers abusing Internet Explorer to enumerate software and detect security products - Jaime Blasco - AlienVault - 2014-07-25

Viewing all articles
Browse latest Browse all 185

Trending Articles