Threat Database Trojans Troj/SWFDL-G

Troj/SWFDL-G

By Domesticus in Trojans

Threat Scorecard

Popularity Rank: 17,140
Threat Level: 90 % (High)
Infected Computers: 623
First Seen: September 19, 2012
Last Seen: October 26, 2025
OS(es) Affected: Windows

Troj/SWFDL-G is a version of the Poison Ivy Trojan that is used in web-based attacks connected with a 'zero day' hole in Internet Explorer to affect targeted Windows PCs. Troj/SWFDL-G exploits the Java vulnerability that takes over most supported versions of Internet Explorer (6, 7, 8 and 9) and Windows Vista, Windows 7 and Windows Server 2003 and 2008 PCs. The vulnerability can be remotely exploited using a website created to target the hole. A remote code execution vulnerability exists in an Internet Explorer function for accessing an object that has been eliminated or not properly allocated. This vulnerability can hijack a system's memory in order to enable hackers run a malicious code with the consent of the Internet Explorer user.

Analysis Report

General information

Family Name: Trojan.Kryptik.VCKAC
Signature status: No Signature

Known Samples

MD5: c2d42a73321f6dc90b95dd99c7a722fa
SHA1: 43aca742ad8210ddfdfeadd81b133d8aabf1963f
SHA256: 59C92918350F10D1AED16AEB261CFF392BD3D354C6AFFE1CB074E6F4AB8D1F99
File Size: 1.93 MB, 1929614 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
File Description Dibbler - a portable DHCPv6 Setup
Product Name Dibbler - a portable DHCPv6

File Traits

  • No Version Info
  • x86

Trending

Most Viewed

Loading...