360TS discovered that a famous download website, 52pk.com, was injected with a flash exploit, CVE-2018-4878. 51CTO.com and cmechina.net, were compromised as well. 360 Security Center analyzed the three injection attacks came from the same criminal group. The attacks are targeting websites that are connected to OpenXs Ads system. OpenX has suspended the maintenance of its system in which lots of known vulnerability have been exposed. Attackers were able to abuse these vulnerabilities via GreenFlash Sundown Exploit Kit.”]

