|
|
Tweet |
Troj/20121889-B Description
Troj/20121889-B is a Trojan that comes supplied with a detection for samples that attempt to exploit a vulnerability in Microsoft XML Core Services which could enable Remote Code Execution (CVE-2012-1889). Troj/20121889-B detection has been recently noticed on the website of the European medical company that was exploiting the CVE-2012-1889 vulnerability. Some files have been embedded into the hijacked website. The file called ‘deploy.html’ contains the vulnerability and loads ‘deployJava.js’, a JavaScript library that determines information about the visiting web browser application. The file ‘deploy.html’ also attempts to run the file named ‘movie.swf’ with the intriguing parameters ‘[?apple=
Type: Trojans
How Can You Detect Troj/20121889-B?
Important Article Disclaimer


Troj/20121889 B
Leave a Comment
Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.