{"id":22694,"date":"2023-08-11T16:11:40","date_gmt":"2023-08-12T00:11:40","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/08\/11\/news-16424\/"},"modified":"2023-08-11T16:11:40","modified_gmt":"2023-08-12T00:11:40","slug":"news-16424","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/08\/11\/news-16424\/","title":{"rendered":"Old exploit kits still kicking around in 2023"},"content":{"rendered":"<p>The year is 2023 and there still are some people using Internet Explorer on planet Earth. More shocking perhaps, is the fact there are still threat actors maintaining exploit kit infrastructure and dropping new malware.<\/p>\n<p>In this quick blog post, we review two well-known toolkits from the past, namely RIG EK and PurpleFox EK with the latest traffic captures we were able to collect.<\/p>\n<h2>RIG EK<\/h2>\n<p>The RIG exploit kit continues to be used by a single threat actor that leverages adult traffic schemes. In this latest instance, it dropped the Lumma Stealer.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2023\/08\/easset_upload_file12229_276004_e.png\" alt=\"RIG EK\" width=\"864\" height=\"232\" style=\"display: block; margin-left: auto; margin-right: auto;\" \/><\/p>\n<h2>PurpleFox EK<\/h2>\n<p>PurpleFox is more than just an exploit kit, it is a complete framework with rootkit capabilities. The exploit kit is one of the delivery mechanisms for the PurpleFox malware.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2023\/08\/easset_upload_file59478_276004_e.png\" alt=\"PurpleFox EK\" width=\"858\" height=\"230\" style=\"display: block; margin-left: auto; margin-right: auto;\" \/><\/p>\n<p>Thank you to researchers at <a href=\"https:\/\/twitter.com\/FirstWatchCyber\" target=\"_blank\">First Watch Security<\/a>&nbsp;for providing information on this attack chain.<\/p>\n<h2>Protection<\/h2>\n<p>Even&nbsp;after all these years, Malwarebytes continues to protect agains these exploit kits targeting vulnerabilities in Internet Explorer, the browser <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2022\/06\/its-official-today-you-can-say-goodbye-to-internet-explorer-or-can-you\" target=\"_blank\">no longer supported by Microsoft<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2023\/08\/easset_upload_file16676_276004_e.png\" alt=\"MBAE\" width=\"763\" height=\"437\" style=\"display: block; margin-left: auto; margin-right: auto;\" \/><\/p>\n<h2>Indicators of Compromise<\/h2>\n<p><strong>RIG EK<\/strong><\/p>\n<pre>adsgoandway[.]xyz<br \/>45.138.27[.]52<\/pre>\n<p><strong>Lumma Stealer payloadd<\/strong><\/p>\n<pre>07e06e8277980a60e595da9cd9e03a4ecd2e8f8bdbd3cf5c930ab878ac5b0836<\/pre>\n<p><strong>Lumma Stealer C2<\/strong><\/p>\n<pre>solopodvip-my[.]xyz<\/pre>\n<p><strong>PurpleFox EK<\/strong><\/p>\n<pre>oernatel[.]shop<br \/>uabeoee.otvidluioad[.]online<br \/>via0[.]com<\/pre>\n<p><strong>Payload<\/strong><\/p>\n<pre>f627070c4cbb03556896601870cf575b1c8f47b062fdfef5c3516ff5a07db40c<\/pre>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2023\/08\/old-exploit-kits-still-kicking-around-in-2023\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding=\"10\">\n<tr>\n<td valign=\"top\" align=\"left\">\n<p>Categories: <a href=\"https:\/\/www.malwarebytes.com\/blog\/category\/threat-intelligence\" rel=\"category tag\">Threat Intelligence<\/a><\/p>\n<p>Tags: exploit kits<\/p>\n<p>Tags: eks<\/p>\n<p>Tags: rigek<\/p>\n<p>Tags: purplefoxek<\/p>\n<p>Internet Explorer may be a thing of the past, but there are still users and threat actors trying to deliver drive-by downloads.<\/p>\n<table width=\"100%\">\n<tr>\n<td align=\"right\">\n<p><b>(<a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2023\/08\/old-exploit-kits-still-kicking-around-in-2023\" title=\"Old exploit kits still kicking around in 2023\">Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2023\/08\/old-exploit-kits-still-kicking-around-in-2023\">Old exploit kits still kicking around in 2023<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11787,10528,29961,11692,12040],"class_list":["post-22694","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-eks","tag-exploit-kits","tag-purplefoxek","tag-rigek","tag-threat-intelligence"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/22694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=22694"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/22694\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=22694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=22694"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=22694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}