HTML_Xploit.V is a malicious HTML file that may be downloaded from remote site(s) by the following malware: HTML_IFRAME.NV.
It may be downloaded from a certain remote site. It may also be hosted on a Web site and run when a user accesses the said Web site.
It takes advantage of a vulnerability in Microsoft XML Core Services to connect to remote URLs to download an infected malicious file detected as PE_VIRUT.BO. More information about the said vulnerability can be found in the following link:
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution
It then saves and executes the downloaded file. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Technical details can be found at this Trend Micro page.
Loading Comments...