Troj/20121889-B

By Sumo3000 in Trojans | 18 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

Troj/20121889-B Description

Troj/20121889-B is a Trojan that comes supplied with a detection for samples that attempt to exploit a vulnerability in Microsoft XML Core Services which could enable Remote Code Execution (CVE-2012-1889). Troj/20121889-B detection has been recently noticed on the website of the European medical company that was exploiting the CVE-2012-1889 vulnerability. Some files have been embedded into the hijacked website. The file called ‘deploy.html’ contains the vulnerability and loads ‘deployJava.js’, a JavaScript library that determines information about the visiting web browser application. The file ‘deploy.html’ also attempts to run the file named ‘movie.swf’ with the intriguing parameters ‘[?apple=‘. Eventually, ‘deploy.html’ loads an iframe to ‘faq.htm’. Troj/20121889-B secures from the ‘deploy.html’ and ‘faq.htm files’.

Type: Trojans

How Can You Detect Troj/20121889-B?

Important Article Disclaimer

ESG Support Center

This entry was last updated on 06/20/12 and posted on 06/20/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.