Attackers using malvertising chain to ditributing the Fallout exploit kit since Jan 2015 via adult websites.
Unlike past infection that discovered back to 2018, current distribution contain new futures including HTTPS support, New landing page format, Powershell to run payload.
It was a Zero-day Flash vulnerability that has been already patched by Adobe in last December security update but still Fallout EK able to exploit the vulnerability to the victims who have not been updated their system since then the patch released.
Fallout Exploit kit Analysis
During the analysis phase, researchers uncovered that Fallout was delivering its payload via Powershell rather than using iexplore.exe.
In order to evade the detection, this exploit calls out the payload URL via Base64 encoded Powershell command.
This technique helps
According to Malwarebytes, What this new development tells us is that exploit kit developers are still monitoring the scene for new exploits and techniques. In 2018, several zero-days for Internet Explorer and Flash Player were found and turned into easily adaptable proof of concepts.
Once the exploit CVE-2018-15982 allows attackers to execute arbitrary commands on vulnerable machines that enabled Flash Player version up to 184.108.40.206.
Current version of the Fallout EK Main motivation to drops the GandCrab ransomware and the campaign started since January 15.
Based Blockchain Network