Thursday, July 14, 2016

Feedly:Malware don't need Coffee. CVE-2016-0189 (Internet Explorer) and Exploit Kit



from Malware don't need Coffee



Spotted by Symantec in the wild  patched with MS16-051 in may 2016, CVE-2016-0189 is now being integrated in Exploit Kit.

Neutrino Exploit Kit :
Here 2016-07-13 but i am being told that i am late to the party.
It's already [CN] documented here

Neutrino after ScriptJS redirector dropping Locky Affid 13

Flash sample in that pass : 85b707cf63abc0f8cfe027153031e853fe452ed02034b792323eecd3bc0f7fd
(Out of topic payload : 300a51b8f6ad362b3e32a5d6afd2759a910f1b6608a5565ddee0cad4e249ce18 - Locky Affid 13 )


Thanks to Malc0de for invaluable help here :)

Files Here: Neutrino_CVE-2016-0189_160714 (Password is malware - VT Link)

Read More :
Patch Analysis of CVE-2016-0189 - 2016-06-22 - Theori
Neutrino EK: fingerprinting in a Flash - 2016-06-28 - Malwarebytes
Web Analytics