Drive-by-Download Du Jour
- Thursday, April 9, 2009, 9:46
- Threat Research
LuckySploit is an exploit framework that’s been in the news recently. As drive-by-downloads go, it lurks behind iframes and foists malware upon unsuspecting users.
One LuckySploit attack we analyzed downloaded the FakeAlert-BY Trojan. So if you visited a Web site today then saw this…
… then you are, unfortunately, infected with FakeAlert-BY, and possibly thanks to LuckySploit.
We detect the LuckySploit downloader as JS/Downloader-BNL in the 5580 DATs, to be released on April 10. We’ve had detection for FakeAlert-BY since the 5545 DATs, released on March 6.
Please update your AV signatures and stay secure!