SWF_BLACOLE.PS
October 09, 2012
PLATFORM:
Windows 2000, Windows XP, Windows Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size:
6,972 bytes
File Type:
SWF
Initial Samples Received Date:
10 Apr 2012
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
NOTES:
This is Trend Micro's detection for malicious .SWF files that contain script which is used to exploit a certain vulnerability in Adobe Flash Player. However, it requires its other components in order to function properly.
This Trojan is a component of the Blackhole Exploit Kit. It is used to load shellcode and other component files.