live casino online

JS_SHELLCODE.YY

March 18, 2010
 Analysis by: adel

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW


This JavaScript has received attention from independent media sources and/or other security firms.

To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be unknowingly downloaded by a user while visiting malicious websites. It may be hosted on a website and run when a user accesses the said website.

  TECHNICAL DETAILS

File Size:

4,096 bytes

File Type:

Script

Memory Resident:

No

Initial Samples Received Date:

10 Mar 2010

Payload:

Downloads files

Arrival Details

This Trojan may be unknowingly downloaded by a user while visiting malicious websites.

It may be hosted on a website and run when a user accesses the said website.

Download Routine

This Trojan takes advantage of the following software vulnerabilities to download possibly malicious files:

After successfully exploiting the said vulnerability, this malware connects to the following URLs to possibly download other malicious files:

  • http://d.{BLOCKED}inrt.us/s.exe

live casino online detects the dowloaded file as:

  • TROJ_SASFIS.VR

Other Details

This Trojan is a zero-day exploit for the following vulnerability:

  • Internet Explorer 6 & 7

  SOLUTION

Minimum Scan Engine:

8.900

VSAPI OPR PATTERN File:

6.933.00

VSAPI OPR PATTERN Date:

18 Mar 2010

Step 1

For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.

Step 2

Close all opened browser windows

Step 3

Remove malware files dropped/downloaded by JS_SHELLCODE.YY

    ?