A short/fast post to answer some questions I got after my tweet about that :
NeoSploit landings before : (note : am able to put a name on this Exploit Kit thanks to Kahu Security )
(almost nothing to see in these wepawet links)
http://wepawet.iseclab.org/view.php?hash=44beb1c3517679fec5157bf174b4e6b8&type=js
http://wepawet.iseclab.org/view.php?hash=6fcf397047639cced72c257c866b1f35&type=js
http://wepawet.iseclab.org/view.php?hash=02a91cc362f6b1f10b22ffe63d08b49a&type=js
Now :
Plugin detect, dictionnary words separated by - and _
Note: as you see I got .htm and .php landings.
(not that much to see in these wepawet links)
http://wepawet.iseclab.org/view.php?hash=7fd1cd73934b179abc97de80afca51d5&type=js
http://wepawet.iseclab.org/view.php?hash=28391ab9e9e281ebeb2316f1428eb8eb&type=js
http://wepawet.iseclab.org/view.php?hash=253137b7ba90eb0425b026c9893d79b8&type=js
For those who wants, Fiddler sessions here :
http://dl.dropbox.com/u/106864056/Fiddlers_5NeoSploit_3old_2new.zip
(note Fiddler had trouble handling response.
You may need to remove some bits)
Want to read more about NeoSploit ?
Neosploit Gets Java 0-Day - Darryl - 2012-09-01 - Kahu Security
Neosploit is Back! - Darryl - 2011-11-26 - Kahu Security
Shedding Light on the NeoSploit Exploit Kit - Daniel Chechik - 2011-01- M86 Security Labs
Some Notes about NeoSploit - 2010-06-04 - Fireeye
NeoSploit landings before : (note : am able to put a name on this Exploit Kit thanks to Kahu Security )
NeoSploit Before |
(almost nothing to see in these wepawet links)
http://wepawet.iseclab.org/view.php?hash=44beb1c3517679fec5157bf174b4e6b8&type=js
http://wepawet.iseclab.org/view.php?hash=6fcf397047639cced72c257c866b1f35&type=js
http://wepawet.iseclab.org/view.php?hash=02a91cc362f6b1f10b22ffe63d08b49a&type=js
Now :
NeoSploit Landings Now - "BH EK2.0 Like" |
Note: as you see I got .htm and .php landings.
(not that much to see in these wepawet links)
http://wepawet.iseclab.org/view.php?hash=7fd1cd73934b179abc97de80afca51d5&type=js
http://wepawet.iseclab.org/view.php?hash=28391ab9e9e281ebeb2316f1428eb8eb&type=js
http://wepawet.iseclab.org/view.php?hash=253137b7ba90eb0425b026c9893d79b8&type=js
For those who wants, Fiddler sessions here :
http://dl.dropbox.com/u/106864056/Fiddlers_5NeoSploit_3old_2new.zip
(note Fiddler had trouble handling response.
Want to read more about NeoSploit ?
Neosploit Gets Java 0-Day - Darryl - 2012-09-01 - Kahu Security
Neosploit is Back! - Darryl - 2011-11-26 - Kahu Security
Shedding Light on the NeoSploit Exploit Kit - Daniel Chechik - 2011-01- M86 Security Labs
Some Notes about NeoSploit - 2010-06-04 - Fireeye