Threat Database Trojans Exp/20124792-B

Exp/20124792-B

By Sumo3000 in Trojans

Threat Scorecard

Ranking: 5,674
Threat Level: 20 % (Normal)
Infected Computers: 1,973
First Seen: January 8, 2013
Last Seen: September 9, 2023
OS(es) Affected: Windows

Exp/20124792-B is an exploit that proliferates via two websites which have been affected by the Internet Explorer zero-day remote code execution vulnerability. The first website serves the Uyghur people of East Turkestan. The Uyghur website encompasses a folder called 'netyanus' which incorporates several files. One of the files, the HTML file, is found as Exp/20124792-B. Internet users who visit the Uyghur website set their PC in danger of being corrupted by Exp/20124792-B. The file called 'news.html', found as Exp/20124792-B, decodes the obfuscated zero-day exploit code inside 'robots.txt', and runs it.

File System Details

Exp/20124792-B may create the following file(s):
# File Name Detections
1. robots.txt
2. today.swf
3. Helps.html
4. xsainfo.jpg
5. deployJava.js
6. news.html
7. exploit.html

URLs

Exp/20124792-B may call the following URLs:

sweetaccess.ru

Trending

Most Viewed

Loading...