WordsJS

- ShadowGate

References:
  • CVE-2018-4878 (Flash Player up to 28.0.0.137) and Exploit Kits - 2018-03-09 - MDNC - Kafeine CVE-2018-4878 WordsJS GreenFlash Sundown Magnitude RIG Fallout Hermes
  • More Reading:

  • [en] OpenX Hacks example (malvertising) - 2015-05-19 - Malekal - Malekal WordsJS Angler
  • This looks like #Fessleak dropping #Malvertising via psychecentral[.]com. Bing referred for Depression test. - 2015-10-12 - Twitter - BelchSpeak WordsJS Angler
  • Music-themed Malvertising Lead To Angler - 2016-01-19 - Zscaler - ThreatLabz WordsJS Angler
  • Top Chilean News Website Emol Pushes Angler Exploit Kit - 2016-05-11 - Malwarebytes - Jérôme Segura WordsJS Angler
  • Is it the End of Angler ? - 2016-06-11 - MDNC - Kafeine Angler Lurk Nuclear SadClowns GooNky EITest WordsJS ScriptJS
  • Domain Shadowing: HillaryNixonClinton.com Shadowed Domains Lead to Neutrino EK - 2016-08-12 - RiskIQ - Mike Wyatt WordsJS Neutrino
  • Talos ShadowGate Take Down: Global Malvertising Campaign Thwarted - 2016-09-01 - Talos - Nick Biasini WordsJS Neutrino
  • Sundown EK from 37.139.47.53 sends Locky Ransomware - 2016-10-17 - Malware-Traffic-Analysis - Brad Duncan WordsJS Bizarro Sundown Locky
  • Yet another Sundown EK variant? - 2016-10-18 - Malwarebytes - Jérôme Segura Bizarro Sundown WordsJS Locky
  • New Bizarro Sundown Exploit Kit Spreads Locky - 2016-11-04 - Trend Micro - Joseph C. Chen - Brooks Li Bizarro Sundown GreenFlash Sundown Locky WordsJS CVE-2016-4117 CVE-2015-7645
  • GreenFlash Sundown exploit kit expands via large malvertising campaign - 2019-06-26 - Malwarebytes - Jérôme Segura GreenFlash Sundown Seon WordsJS
  • Shadowgate Returns to Worldwide Operations With Evolved Greenflash Sundown Exploit Kit - 2019-06-27 - Trendmicro - Joseph C. Chen GreenFlash Sundown WordsJS CVE-2018-15982