Home Malware Programs Trojans Troj/20121889-B

Troj/20121889-B

Posted: June 20, 2012

Threat Metric

Threat Level: 10/10
Infected PCs: 9
First Seen: June 22, 2012
Last Seen: November 12, 2020
OS(es) Affected: Windows

Troj/20121889-B is a Trojan that comes armed with a detection for samples that try to exploit a vulnerability in Microsoft XML Core Services which could allow Remote Code Execution (CVE-2012-1889). Troj/20121889-B detection has been recently reported on the website of the European medical company that was exploiting the CVE-2012-1889 vulnerability. A few files have been inserted into the compromised website. The file named 'deploy.html' includes the vulnerability and loads 'deployJava.js', a JavaScript library that determines information about the visiting browser program. The file 'deploy.html' also tries to execute the file named 'movie.swf' with the intriguing parameters '[?apple='. In the end, 'deploy.html' loads an iframe to 'faq.htm'. Troj/20121889-B protects against the 'deploy.html' and 'faq.htm files'.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



faq.htm File name: faq.htm
Size: 413B (413 bytes)
MD5: 482facda25d53e1aa7fefb9d307100d6
Detection count: 2
Mime Type: unknown/htm
Group: Malware file
Last Updated: June 28, 2012
Loading...