Threat Database Trojans Troj/20121889-B

Troj/20121889-B

By Sumo3000 in Trojans

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 4
First Seen: June 22, 2012
Last Seen: November 12, 2020
OS(es) Affected: Windows

Troj/20121889-B is a Trojan that comes supplied with a detection for samples that attempt to exploit a vulnerability in Microsoft XML Core Services which could enable Remote Code Execution (CVE-2012-1889). Troj/20121889-B detection has been recently noticed on the website of the European medical company that was exploiting the CVE-2012-1889 vulnerability. Some files have been embedded into the hijacked website. The file called 'deploy.html' contains the vulnerability and loads 'deployJava.js', a JavaScript library that determines information about the visiting web browser application. The file 'deploy.html' also attempts to run the file named 'movie.swf' with the intriguing parameters '[?apple='. Eventually, 'deploy.html' loads an iframe to 'faq.htm'. Troj/20121889-B secures from the 'deploy.html' and 'faq.htm files'.

SpyHunter Detects & Remove Troj/20121889-B

File System Details

Troj/20121889-B may create the following file(s):
# File Name MD5 Detections
1. faq.htm 482facda25d53e1aa7fefb9d307100d6 0

Trending

Most Viewed

Loading...