Malware

Exploit kit

Exploit kit is a server-side toolbox that fingerprints a visitor's browser and plugins and then tries known vulnerabilities until one works. If one does, it delivers malware.

How it is measured

You see it in the redirect chain: a landing page that profiles the browser, then a hop that serves a Flash, Java, or JavaScript exploit tuned to the version it found. Sandbox traces show a quick series of unusual resource requests and then a binary download.

Researchers label kits by traits: URL pattern, obfuscation style, and the CVEs they target.

Worked example

A compromised dental clinic site includes a hidden iframe to `gate.loader-host.top`. In a lab browser with an old Flash plugin, the chain shows three requests in two seconds and ends with an executable download. In a patched modern browser, the same chain ends at a blank page.

The clinic cleans the iframe from its footer template and the lab report is used to block the gate domain.

How it differs

An exploit kit chooses and fires exploits. A drive-by download is the outcome when it works. A zero-day is a flaw with no patch; most kits rely on older, patched flaws because many users lag behind. The kit is infrastructure that someone rents; the exploit is only one piece inside it.

Common errors

Thinking kits only use zero-days. Believing a patched browser makes you immune to everything. Looking only at the final payload and missing the gate. Confusing the compromised site with the kit's server. Assuming kits died with Flash.

In practice

Keep browsers, plugins, and the operating system current on every machine you manage. For your site, scan for hidden frames and unknown script hosts. If you find a gate, report the domain and clean the way it was injected.

See also

Zero-day, Drive-by download

Sources

Count this on a real site.

Watch my website