French Security Incident Response Team

FrSIRT   

      

   français French  anglais English

 
Vulnerability Notification Service
FrSIRT Partner Program
14-Day Free Trial
Contact FrSIRT Sales Dept.
 

Security Advisories
Linux Security Advisories
Virus and Threats Advisories
Latest Security News
Latest Zero Day Threats
Advisories and vulnerabilities by Vendor
Advisories and vulnerabilities by Keyword
 

Report a security incident
Report a new vulnerability
Security Mailinglist
 

Our Company
FrSIRT in the News
Advertise on FrSIRT.COM
Security Researchers and Exploit Writers Jobs
Contact Us

TROJ_REALPLAY.BR Information


Alert ID : FrSIRT/ALRT-2008-02771
Aliases : Exploit.JS.RealPlr.im (Kaspersky) - Downloader (Symantec) - JS/Agent.ES (Avira)
Size : 3877 bytes
Rated as : Low Risk 
Release Date : 2008-05-09
Last Update : 2008-05-19

Description

This Trojan may be downloaded after a series of redirections triggered by JS_DLDR.AW. It takes advantage of a known vulnerability in several versions of the media player RealPlayer. The said vulnerability causes a stack overflow and allows the download of possibly malicious files on the affected system. More information on this vulnerability can be found on here. Before exploiting the above-mentioned vulnerability, this Trojan first checks if the affected machine is running on Windows 2000 or Windows XP with Internet Explorer 6 or 7. It also checks if RealPlayer is installed on the system and what version of the player is installed to determine the first few bytes of shell code that it writes on the affected system. It uses a certain import function to send the shell code to the installed RealPlayer application, thus triggering the said exploit. Once it successfully exploits the said vulnerability, this Trojan connects to a certain URL to download TROJ_AGENT.AKVP. As a result, the routines of the downloaded Trojan may be exhibited on the system. For additional information about this threat, see:SolutionTechnical DetailsStatistics Description created:May. 7, 2008 8:47:23 AM GMT -0800 Search a new malwareTell us how we did. Take our quick survey. Search: Worldwide This site is for customers in the United States & Canada . **. **frsirt** Contact Us Careers About Us . **. **frsirt** Home Home & Home Office Small Business Medium Business Enterprise Business Partners . **. **frsirt** Quick Links See All Products & Solutions Support Purchase Update Center . **. **frsirt** Copyright (c) 1989-2007 Trend Micro Incorporated. All rights reserved.

References

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_REALPLAY.BR

Credits

Reported by Trend Micro

ChangeLog

2008-05-09 - Initial Release
2008-05-19 - Updated Aliases

Disclaimer

The information contained herein was obtained from third party sources and is solely based upon the data available at the time of publication.

 
 

Search

      

Mailinglist

    
 

Oracle Products Command Execution and SQL Injection Vulnerabilities

Oracle Products Multiple Code Execution and SQL Injection Vulnerabilities

Oracle Database "PITRIG_DROPMETADATA" Buffer Overflow Vulnerability

Oracle Products Multiple Code Execution and SQL Injection Vulnerabilities

Oracle JInitiator ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities

Oracle Products Multiple Remote Command Execution and SQL Injection Vulnerabilities

Oracle Products Multiple Remote Command Execution and SQL Injection Vulnerabilities

Microsoft Internet Explorer Printing Cross-Zone Scripting Vulnerability

Microsoft Malware Protection Engine Remote DoS Vulnerability (MS08-029)

Microsoft Publisher Object Handler Validation Vulnerability (MS08-027)

Microsoft Office Multiple Code Execution Vulnerabilities (MS08-026)

Microsoft Windows XP I2O Filter Privilege Escalation Vulnerability

Microsoft Internet Explorer DisableCachingOfSSLPages Weakness

Microsoft Windows CE Image Handling Code Execution Vulnerabilities

Cisco BBSM "msg" Parameter Cross Site Scripting Vulnerability

Cisco Unified Presence Remote Denial of Service

Cisco Unified Communications Manager Denial of Service

Cisco Content Switching Module Remote Denial of Service Vulnerability

Cisco Network Admission Control Shared Secret Disclosure Vulnerability

Cisco UC Disaster Recovery Framework Command Execution Vulnerability

Cisco IOS Denial of Service and Information Disclosure Vulnerabilities

Copyright 2003-2008 © FrSIRT.COM - Privacy Policy