2012-10-18 - Evolution

Stamp EK (aka SofosFO) now showing "Blackhole 2.0 Like" landing pages

<edit4 2013-09-09> This Exploit Kit is GrandSoft : Readmore</edit4>
A short/fast post to answer some questions I got after my tweet about that :

<edit1 28/10/12> Have been told by Paul that the browser exploit pack i am referring here is not Neosploit. As I have no name to put on that, I will use arbitrarily : Stamp EK (Edit2: have been informed that Emerging Threats is calling it : SofosFO, cf link and credits at the end ) . If anyone use another name for that, please contact me.

I mainly based my naming on : http://urlquery.net/report.php?id=198525
URLQuery report on this Stamp EK. False positive for NeoSploit

NeoSploit Stamp EK landings before :

Stamp EK Landings Before

(almost nothing to see in these wepawet links)

Now :
Stamp EK Landings Now - "BH EK2.0 Like"

Plugin detect, dictionnary words separated by - and _
Note: as you see I got .htm and .php landings.

(not that much to see in these wepawet links)

For those who wants, Fiddler sessions here  :
http://goo.gl/5sEpY (Mega)

If you have information on what I called Stamp EK...please contact me.
<edit2 01/11/12>
Chris Wakelin told me that they name it : SofosFO at Emerging Threats and told me why.
Sophos sucks? Being insulted by malware authors can be the best reward - Fraser Howard - 2012-08-24 - Naked Security (Sophos)

<edit4 2013-03-12>
SofosFO seems to be a good name (even if we sometimes see some : onecareFO or others) :

"Dear Sofos, xyle tebe nado? Ya ne ponimayu. Otebis please ot nas! ThankYou"
SofosFO/Stamp EK landing 2013-03-11

