Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    September 2006
    S M T W T F S
    « Aug   Oct »
     12
    3456789
    10111213141516
    17181920212223
    24252627282930
  • About Us
    Malware Blog > 2006 > September> 19

    Archive for September 19th, 2006




    Sunbelt has just discovered a new IE zero day being used in the wild. The zero day exploit makes use of a vulnerability in the Vector Markup Language (VML) inside Internet Explorer to overflow a buffer and inject a shellcode.


    I will update this as research on the said subject is still on going.


    Update (Jovs, Tue, 19 Sep 2006 10:37:07 PM)


    For those who don’t know, the vulnerable dll exploited by this zero day is VGX.DLL which is used by Internet Explorer for processing Virtual Markup Language.


    Sunbelt has proposed turning off Javascripting to mitigate the exploit. Or you can just use an alternative browser like Firefox.


    Microsoft has already been informed about the vulnerability, so far there isn’t a patch available yet, but give them time, it is a zero day after all.


    This blog will be updated for the malware name given to the exploit code.



    Update (Chachi, Wed, 20 Sep 2006 03:08:05 AM)


    The exploit code will now be detected as EXPL_EXECOD.A and the executable files will be detected as TROJ_AGENT.FAC, TROJ_DELF.DBC, TROJ_DLOADER.EES.


    These are now detected using Control Pattern 3.764.02


     
    Posted in Uncategorized | Comments Off


    Sep19
    11:52 am (UTC-7)   |    by

    As of this writing we have already received a total of 1,335 Samples in a couple of hours. Trend Micro has already detected this threat as TROJ_CLAGGE.B using OPR 3.759.00.


    The malware comes as an attachment to emails with the filename Rechnung.zip or Rakningen.zip(7,028 Bytes). Please be wary of emails you receive with those attachments, do not atempt to open them. If you want more information on what the malware is capable of check our Virus encyclopedia here.


    We are still looking into the details of this spammed malware, as of now please be very careful of attachments with the aforementioned filenames in your inbox.

     
    Posted in Uncategorized | Comments Off


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice