The shellcode used in the IE attack downloads a GIF image from the command and control server then decrypts the portable executable file hidden in the image. “The PE file also appeared to be a ...