This variant of the LightsOut exploit kit uses a number of Java vulnerabilities, and targets multiple browsers. The primary goal is to drop & execute a downloader executable, which in turn downloads and executes more malware samples. These secondary malware samples are run in a sequence, and do some information harvesting, and potentially exfiltrate the information harvested. The first stage leverages a holdover technique from the Internet Explorer 6 era the HtmlDlgSafe helper ActiveX control; to check if a list of over 700 fonts are available to the browser.”]
Source: https://blog.talosintelligence.com/2014/05/continued-analysis-of-lightsout-exploit.html

