When link is followed …
• Runs Malicious JavaScript (Troj/Pysme-DL)
• Exploits IE Vulnerability
• Downloads Troj/Dropper-MH
• Drops Troj/Bckdr-PPY used to ‘hide’ processes
• Also drops Troj/Proxy-EN which tells the backdoor what tohide
• Once installed, cannot be “seen”
• Main purpose – Troj/Proxy-EN used to ‘relay’ spam
Read more in this PDF by Sophos--
http://icsecurity.di.uniroma1.it/sto...rrisSophos.pdf
Doesn't appear people here care too much, but if you do, check your trades/links.
Your income depends on it.