This Trojan executes when a user accesses certain websites where it is hosted.
File size: 231 bytes
File type: JS
Memory resident: No
Initial samples received date: 25 Jan 2012
Arrival Details
This Trojan executes when a user accesses certain websites where it is hosted.
It may be downloaded from the following remote sites:
- http://{BLOCKED}s.{BLOCKED}p.com/is.js
NOTES:
It is a component of a malware which Trend Micro detects as HTML_EXPLT.QYUA which leverages CVE-2012-0003:
It aids in decrypting the shellcode embedded in the body of HTML_EXPLT.QYUA. As a result, malicious payload of HTML_EXPLT.QYUA are exhibited on the affected system.
Connect with us on
| | | |