Home Malware Programs Trojans JS_BLACOLE.MT

JS_BLACOLE.MT

Posted: June 13, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 54
First Seen: June 13, 2013
Last Seen: December 30, 2021
OS(es) Affected: Windows

JS_BLACOLE.MT is a Trojan that proliferates via hacked Japanese websites. One of the hacked websites carries an obfuscated JavaScript, detected as JS_BLACOLE.SMTT, which is generated to load a hidden iframe that loads behind the target computer user's Internet browser. The hidden iframe loads a .PHP file, found as JS_BLACOLE.MT, that checks which applications are installed on the victim's PC. After checking, it then loads the appropriate exploits. These cause the download of harmful PDF files, which exploit an old vulnerability (CVE-2010-0188) in Adobe Reader and Acrobat. Other programs corrupted for exploits cover Java and Flash. This behavior specifies that the cybercrook used the Blackhole Exploit Kit in these attacks.

Loading...