Trojan Utilizes an unpatched IE flaw

The release of a Trojan Horse that utilizes an unpatched Internet Explorer hole has rumours that Microsoft may decide to release what is described as: “An emergency out-of-cycle security patch”. The Trojan: “Delf-DH Trojan downloader” uses an Internet Explorer back-door to infect the computers of unprotected users of Windows who may accidentally hit onto maliciously constructed websites.

When infected, Delf-DH Trojan downloader downloads other malware onto your computer system which changed crucial settings in order to observe user activity and redirect surfers onto porn sites.

Delf-DH Trojan downloader depends upon a flaw in the way Internet Explorer handles requests to the window() object. This attack is also used in anger by VXers.

If using completely patched Windows 2000 or Windows XP systems you are still vulnerable to attack. “US-CERT strongly encourages Windows users to disable Active Scripting.”

Leave a comment

Your email address will not be published. Required fields are marked *