Home / malwarePDF  

Exploit:JS/Mult.BN


First posted on 18 June 2009.
Source: SecurityHome

Aliases :

There are no other names known for Exploit:JS/Mult.BN.

Explanation :

Exploit:JS/Mult.BN is a generic detection of obfuscated malicious code that may be used to exploit vulnerabilities in different software, in order to download and execute arbitrary files from a remote server.

Symptoms
There are no obvious symptoms that indicate the presence of this malware on an affected machine.

Exploit:JS/Mult.BN is a generic detection of obfuscated malicious code that may be used to exploit vulnerabilities in different software, in order to download and execute arbitrary files from a remote server.

Installation
Exploit:JS/Mult.BN may be embedded in JavaScript, and as such may be hosted in various formats such as in HTML pages on websites, or in PDF files.

Payload
Downloads and executes arbitrary filesIf the vulnerability is successfully exploited, Exploit:JS/Mult.BN tries to download a file from remote server to the local computer and then executes it.
Exploit:JS/Mult.BN has been observed to exploit the following vulnerabilities in Adobe Acrobat and Reader:

  • CVE-2007-5659
  • CVE-2008-2992
  • CVE-2009-0927


  • Analysis by Shawn Wang

    Last update 18 June 2009

     

    TOP