
The Dell Sonicwall UTM research team has been observing a recent increase in drive-by-download infections. These infections utilize the Blackhole Exploit and usually arrive in the form of spam masquerading as a legitimate company notification containing a malicious link.
The spam observed uses the following text and contains a malicious link:

The link takes the user to a malicious webpage that pretends to load a doc file containing further information:

The webpage contains javascript code the employs the Blackhole Exploit :

The exploit causes the download of a Cridex Banking Trojan variant:

The Trojan creates the following files on the filesystem:
The Trojan creates the following registry key in the Windows registry to enable startup after reboot:
SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:

Share This Article

An Article By
An Article By
Security News
Security News