Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Angler EK: More Obfuscation, Fake Extensions, and Other Nonsense

released on 2015-06-05 @ 06:47:46 PM
Late last week Talos researchers noticed a drastic uptick in Angler Exploit Kit activity. We have covered Angler previously, such as the discussion of domain shadowing. This exploit kit evolves on an almost constant basis. However, the recent activity caught our attention due to a change to the URL structure of the landing pages. This type of change doesn’t occur often and was coupled with some other interesting tidbits including how the HTTP 302 cushioning has evolved and the payload of another ransomware has changed.