Threat Database Trojans JS_BLACOLE.SMTT

JS_BLACOLE.SMTT

By Domesticus in Trojans

JS_BLACOLE.SMTT is a Trojan that circulates via hacked Japanese websites. One of the hacked websites encompasses an obfuscated JavaScript, found as JS_BLACOLE.SMTT, which is generated to load a hidden iframe that loads behind the target computer user's Internet browser. The hidden iframe loads a .PHP file, found as JS_BLACOLE.MT, that checks which programs are installed on the attacked PC user's computer. After checking, it then loads the appropriate exploits. These cause the download of harmful PDF files, which exploit an old vulnerability (CVE-2010-0188) in Adobe Reader and Acrobat. Other applications contaminated for exploits incorporate Java and Flash. This behavior specifies that the cybercrook used the Blackhole Exploit Kit in these attacks.

Trending

Most Viewed

Loading...