Blog | G5 Cyber Security

Neutrino EK: more Flash trickery

Neutrino EK adds fingerprinting to the infection chain by crafting a special Flash file and uploading it on compromised hosts. This ensures proper filtering of non desirable traffic even before the gate to the exploit kit. The rogue SWF file is hosted on the hacked website, and for all intents and purposes looks innocuous as it hides in plain sight within other media types. This is not the EITest campaign though, which does have an intermediary redirection mechanism with Flash. Instead, the rogue Flash file is. hosted on hacked website. This Flash file performs the same fingerprinting that we saw before within the NeutRino exploit kit itself.”]

Source: https://blog.malwarebytes.com/threat-analysis/exploits-threat-analysis/2016/08/neutrino-ek-more-flash-trickery/

Exit mobile version