PULSE NAME
APT Group Wekby Leveraging Adobe Flash Exploit
WHITE Wekby AlienVault 2015-07-09 Modified: 2017-08-24
7
IOCs
LOW VOLUME
As if the recent breach and subsequent public data dump involving the Italian company Hacking Team wasn’t bad enough, it all gets just a little bit worse. Emerging from the bowels of Hacking Team data dump was a Flash 0-day exploit (CVE-2015-5119) that was just patched today by Adobe as covered in APSB15-16. The exploit has since been added into the Angler Exploit Kit and integrated into Metasploit. However, not to be out done, APT attackers have also started leveraging the exploit in targeted spear phishing attacks as well. Before we start dishing the details, there is going to be one main takeaway from this blog post: If you haven’t already, update/patch your Adobe Flash now.
Indicators of Compromise (2 / 7 total)
All hostname FileHash-MD5 FileHash-SHA1 CVE
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 cfbcb83f8515bd169afd0b22488b4430 2017-08-24
FileHash-MD5 079a440bee0f86d8a59ebc5c4b523a07 2017-08-24