Threat behavior
Trojan:JS/Redirector.V is a detection for trojan Java scripts that download and execute malicious Shockwave Flash (SWF) files. The malicious SWF files are crafted to exploit “
Adobe Flash Player Invalid Pointer Vulnerability”, and detected by Microsoft antivirus solutions as Exploit:Win32/APSB08-11.gen!A.
Installation
Trojan:JS/Redirector.V could be stored as an embedded script in malicious Web pages. When a user visits the page, the script could execute exploit code that targets specific versions of Adobe Flash Player.
The trojan identifies the Adobe Flash Player version and executes specific SWF version exploit code based on the returned revision version number, as in the following examples:
i115.swf - 9.0.115.0 exploit
i64.swf - 9.0.64.0 exploit
i47.swf - 9.0.47.0 exploit
i45.swf - 9.0.45.0 exploit
i28.swf - 9.0.28.0 exploit
i16.swf - 9.0.16.0 exploit
Payload
Executes Arbitrary Code
Successful exploitation of the vulnerability results in execution of arbitrary code. The payload code could be any number of file operation actions which could include the download and execution of additional malware.
Additional Information
For more information regarding the Adobe Flash Player vulnerability, please visit the following links:
Analysis by Shali Hsieh
Prevention