The Internet Explorer 0-day CVE 2014-1776 is an Internet Explorer vulnerability that uses Javascript to cause exploitation. There was almost no obfuscation of the code, with names like “dword2data” and “arrLen” showing up without so much as a base64 encoding in sight. The shellcode was encrypted using RC4, which is an extra level of obfuscation we don’t commonly see. The end result is that the shellcode calls out to download a page from inform.bedircati.com.”]
Source: https://blog.talosintelligence.com/2014/05/anatomy-of-exploit-cve-2014-1776.html

