IE 0-day exploit

ok, so the supposedly IE7  vulnerability is also applicable to other versions.

Check out MS advisory 961051

Other domains that are also exploiting this vulnerability are listed in shadowserver.

Notice that the shellcode of IE7 exploit is encrypted.

ie7 exploit encrypted shellcode

Disassembly of the shellcode shows that each byte is xored with 21h.

To decrypt the shellcode, a simple perl script can be applied to the unicode


A hexdump of the decrypted shellcode shows where it will retrieve the malware:



  1. The patch to the IE vulnerability is already released –

    If you are still procrastinating, maybe this report about IE exploit via Word doc may change your mind –

