JAVA_BLACOLE.CI

 Analysis by: Nice Yutuc

 ALIASES:

EXP/CVE-2011-3544 (AntiVir), Exploit.Java.Blacole!IK (Emisoft)

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW


This Trojan may arrive bundled with malware packages as a malware component. It may be hosted on a website and run when a user accesses the said website.

  TECHNICAL DETAILS

File Size:

7,111 bytes

File Type:

Java Class

Initial Samples Received Date:

29 Jan 2012

Arrival Details

This Trojan may arrive bundled with malware packages as a malware component.

It may be hosted on a website and run when a user accesses the said website.

NOTES:

This Trojan downloads a possibly malicious file from a certain URL. The URL where this malware downloads the said file depends on the parameter passed on to it by its components. In order to execute properly, this malware needs the whole .JAR file, where this file is bundled from.