New IE Zero-Day used in targeted attacks

From Botnets.fr
Jump to navigation Jump to search

(Publication) Google search: [1]

New IE Zero-Day used in targeted attacks
Botnet Pirpi
Malware
Botnet/malware group
Exploit kits
Services
Feature
Distribution vector
Target
Origin
Campaign
Operation/Working group
Vulnerability
CCProtocol
Date 2010 / 2010-11-08
Editor/Conference Symantec
Link http://www.symantec.com/connect/blogs/new-ie-zero-day-used-targeted-attacks (Archive copy)
Author Vikram Thakur
Type

Abstract

Things have been pretty rough in the Response world the past few weeks. The number of exploits taking advantage of unknown and unpatched vulnerabilities has been breathtaking.

One such case started few days ago when we received information about a possible exploitation using older versions of Internet Explorer as targets. Hackers had sent emails to a select group of individuals within targeted organizations. Within the email, the perpetrators added a link to a specific page hosted on an otherwise legitimate website. The hackers had gotten access to the website account and uploaded content without the owners knowing.

Bibtex

 @misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2010BFR1207,
   editor = {Symantec},
   author = {Vikram Thakur},
   title = {New IE Zero-Day used in targeted attacks},
   date = {08},
   month = Nov,
   year = {2010},
   howpublished = {\url{http://www.symantec.com/connect/blogs/new-ie-zero-day-used-targeted-attacks}},
 }