JS_SHELLCODE.YY
Windows 2000, XP, Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This JavaScript has received attention from independent media sources and/or other security firms.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be unknowingly downloaded by a user while visiting malicious websites. It may be hosted on a website and run when a user accesses the said website.
TECHNICAL DETAILS
4,096 bytes
Script
No
10 Mar 2010
Downloads files
Arrival Details
This Trojan may be unknowingly downloaded by a user while visiting malicious websites.
It may be hosted on a website and run when a user accesses the said website.
Download Routine
This Trojan takes advantage of the following software vulnerabilities to download possibly malicious files:
After successfully exploiting the said vulnerability, this malware connects to the following URLs to possibly download other malicious files:
- http://d.{BLOCKED}inrt.us/s.exe
live casino online detects the dowloaded file as:
- TROJ_SASFIS.VR
Other Details
This Trojan is a zero-day exploit for the following vulnerability:
- Internet Explorer 6 & 7
SOLUTION
8.900
6.933.00
18 Mar 2010
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.
Step 2
Close all opened browser windows
Step 3
Remove malware files dropped/downloaded by JS_SHELLCODE.YY
- ?