JAVA_DLOADR.WH
Exploit:Java/CVE-2008-5353.EQ (Microsoft), Troj/JavaDl-V (Sophos)
Windows 2000, Windows XP, Windows Server 2003


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives as a Java Applet component of a malicious Java archive file (.JAR) that is hosted in a malicious website.
It downloads files. It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
TECHNICAL DETAILS
NOTES:
This Trojan arrives as a Java Applet component of a malicious Java archive file (.JAR) that is hosted in a malicious website.
It executes the file specified in the parameter slink. It downloads the file specified in the parameter sdata. It saves the file it downloads using the following name:
- %User Temp%\{random file name}.tmp
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.

