Infection Channel: Downloaded from the Internet
This malicious HTML file exploits a zero-day vulnerability in Internet Explorer 7, 8, and 9. The exploit leads to the dropping of a PoisonIvy backdoor. PoisonIvy backdoors are known to be widely used in targeted malware attacks.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

It then loads a malicious Flash file, Moh2010.swf. As a result, malicious routines of the component file are exhibited on the affected system. The malicious Flash file is detected by Trend Micro as either SWF_DROPPR.II, SWF_DROPPR.IJ, SWF_DROPPER.IK, or SWF_DROPPR.IL.
This Trojan may be hosted on a website and run when a user accesses the said website.
File size: Varies
File type: HTML, HTM
Initial samples received date: 17 Sep 2012
Payload: Executes files
Arrival Details
This Trojan may be hosted on a website and run when a user accesses the said website.
NOTES:
This malware checks the user's browser version. It targets Internet Explorer versions 7 and 8 on Windows XP. Some variants of this malware also targets Internet Explorer versions 8 and 9 on a 32-bit Windows 7 whose Java version is neither 6 nor 7.
It loads the malicious Flash file Moh2010.swf, which is detected by Trend Micro as one of the following:
- SWF_DROPPR.II
- SWF_DROPPR.IJ
- SWF_DROPPR.IK
- SWF_DROPPR.IL
Connect with us on
| | | |