Hi folks,
One of our researchers recently discovered that the Liberty exploit kit included a fairly new exploit from November 2009 … http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867 .
The fact that there was something fairly new in terms of exploits was interesting to start with, but then we looked at the text on the exploit page….
Lehman Brothers?! Coffee Party??!! Holy Activists, Batman!!! It’s politically motivated!!!!
Then we looked at the stats page (all these toolkits come with a sophisticated admin page), and saw that the top referrer was ad.yieldmanager.com! Holy Advertisers, Batman! Activists who know how to use exploit kits, _and_ the ad network!!!
...