
The curious case of a Sundown EK variant dropping a Cryptocurrency Miner

January 9, 2017


We recently encountered an atypical case of Sundown EK in the wild – usually the landing page is obfuscated, but in this case there was plain JavaScript. The exploit was dropping some malicious payloads that we took for further analysis. It turned out that they are also atypical by many means. In this article, we will describe the details of our investigation.

Exploit Kit
This exploit kit has a different serving infrastructure than what we are used to seeing, but it is essentially the same Sundown EK that we know.

Read More on Malwarebytes