Java exploit: CVE-2013-0422 and CVE-2012-1723 were spotted within the jar file. Split happens within the file itself, in a class where we see the two (unobfuscated) strings that correspond to our file names: The bytes from each file are read and then split: The files are finally executed: It could deliver all sorts of payload (banking trojan, spambot, etc). Both files are detected by Malwarebytes Anti-Malware.”]
Source: https://blog.malwarebytes.com/threat-analysis/2013/04/redkit-exploit-kit-does-the-splits/

