LevelBlue + SentinelOne: Global Partnership to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

Sakura Exploit Kit 1.1

Even though it's sometimes easy to forget that there are exploit kits other than BlackHole, other groups still strive for sales in the exploit kits market. So, while some of those toolkits are sophisticated enough to compete head-to-head with BlackHole, such as Redkit (which isn't red anymore), others provide lower-end solutions which typically costs less. One of those lower-end toolkits would be Sakura.

12398_e86129a0-cab4-413d-b822-ed5fcf84ac22

Today we've come across a new version of this toolkit, labeled 1.1.

The toolkit attack code isn't obfuscated except for some character encoding:

11778_c93c595d-f71e-4b29-a87f-1e9f613f742b

The included PDF file attempts to exploit the libTiff (CVE-2010-0188) vulnerability while the Java applet attempts to exploit CVE-2012-0507.

Needless to say, customers of LevelBlue Secure Web Gateway (SWG) are protected by default.

ABOUT LEVELBLUE

LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.

Latest Intelligence

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo