TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
JS_REALPLAY.AT
Overview

Malware type: JavaScript

Aliases: Exploit.JS.Agent.oh (Kaspersky),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: Yes

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

This JavaScript may be hosted on a Web site and run when a user accesses the said Web site. It is a specially-crafted HTML script that takes advantage of a vulnerability in certain software.

It exploits a vulnerability in the file rmoc3260.dll, causing memory corruption and execution of arbitary codes. More information can be found in the following Web site:

Once the vulnerability is exploited, this JavaScript then downloads a file detected by Trend Micro as BKDR_HUPIGON.CYH. It then executes the downloaded file. As a result, malicious routines of the downloaded files are exhibited on the affected system.

For additional information about this threat, see:
Solution
Technical Details

Description created: May. 18, 2008 2:26:54 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.