This Trojan executes when a user accesses certain websites where it is hosted.
File size: 38,068 bytes
File type: MID
Memory resident: No
Initial samples received date: 25 Jan 2012
Arrival Details
This Trojan executes when a user accesses certain websites where it is hosted.
It may be downloaded from the following remote sites:
- http://{BLOCKED}s.{BLOCKED}op.com/baby.nid
NOTES:
It is a component of a malware which Trend Micro detects as HTML_EXPLT.QYUA.
It is a specially crafted MIDI file that aids in exploiting the following vulnerability:
As a result, the malicious payload of HTML_EXPLT.QYUA are exhibited on the affected system.
Connect with us on
| | | |