Skip to main content
Skip to main content
Microsoft Security Intelligence
492 entries found. Displaying page 1 of 25.
Updated on Dec 10, 2012

TrojanDownloader:Java/OpenConnection is the detection for a Java based malware family that exploits a vulnerability discussed in CVE-2010-0094. The vulnerability affects Java Runtime Environment (JRE) up to and including version 6 release 18, and makes it possible for untrusted code to gain browser security privileges under the user's account.

A user may encounter threat from this family when visiting a compromised website. If the user is using a vulnerable version of Java, successful exploitation resulting in infection can occur. Threats such as this can often be avoided by ensuring the most up to date software is installed on the computer. To prevent reinfection and avoid similar exploits, make sure up to date security patches are applied to the Java Runtime Environment.

Update vulnerable Java applications

This threat exploits a known vulnerability in Java Runtime Environment. After removing this threat, make sure that you install the updates available from the vendor. You can read more about this vulnerability in Java, as well as where to download the software update from the following links:

It may be necessary to remove older versions of Java that are still present. Keeping old and unsupported versions of Java on your system presents a serious security risk. To read more about why you should remove older versions of Java, see the following information.

Alert level: severe
Updated on Mar 04, 2011
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.GC is a detection for a Java applet that attempts to download and execute arbitrary files from a remote host. It often works in conjunction with Exploit:Java/CVE-2010-0094, which attempts to exploit a vulnerability in the Java Runtime Environment (JRE). This vulnerability allows an unsigned Java applet to gain elevated privileges and potentially have unrestricted access to a host system, outside its "sand box" environment.
 
The vulnerability can be exploited by malware to gain access to a user's computer to download and install malicious programs. The malware installation may occur when a malicious Java applet is executed by a vulnerable JRE. This scenario can occur when a user visits a malicious webpage that hosts such an applet. Note that a number of legitimate websites could be compromised or unwillingly host a malicious applet through advertising frames which could redirect to or host a malicious Java applet.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.IT is the detection for an obfuscated Java applet that attempts to download and execute files from a remote web site. It often works in conjunction with Exploit:Java/CVE-2010-0094, which exploit a vulnerability in the Java Runtime Environment (JRE).
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.JR is a trojan Java applet that allows the downloading and execution of arbitrary and malicious files.
Alert level: severe
Updated on Dec 09, 2012

TrojanDownloader:Java/OpenConnection.PM is an obfuscated Java applet that attempts to download and execute arbitrary files from a remote host. It is usually bundled with other malware that exploits the vulnerability described in CVE-2010-0840.

The vulnerability allows this malware to download and run arbitrary files. The trojan may also be encountered when visiting a compromised or malicious webpage with a vulnerable computer.

The following versions of Java are vulnerable to this exploit:

  • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux; Java SE
  • JDK 5.0 Update 23 and earlier for SolarisJava SE
  • SDK 1.4.2_25 and earlier for SolarisJava SE
  • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and LinuxJava for Business
  • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and LinuxJava for Business
  • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and LinuxJava for Business
Install updates to prevent infection

This malware exploits known vulnerabilities.

Make sure that you install all available updates from the vendor and remove old versions of Java in order to avoid this exploit. You can read more about this vulnerability and download software updates from these links:

Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.ES is the detection for an obfuscated Java class that is part of a bundled malicious Java applet. The applet exploits the vulnerability described in CVE-2008-5353 and can be used to download and run arbitrary files from a malicious website.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.JQ is the detection for an obfuscated Java applet that attempts to download and execute files from a remote web site. It often works in conjunction with Exploit:Java/CVE-2010-0094, which exploit a vulnerability in the Java Runtime Environment (JRE).
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.AO is a trojan Java applet that allows the downloading and execution of arbitrary and malicious files.
Alert level: severe
Updated on Oct 04, 2011

TrojanDownloader:Java/OpenConnection.OS is a Java applet trojan that may allow the downloading and execution of arbitrary malicious files.

Alert level: severe
Updated on Oct 05, 2011

TrojanDownloader:Java/OpenConnection.OU is an obfuscated Java class applet trojan that attempts to download and execute arbitrary files from remote servers.

Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.HH is the detection for an obfuscated Java applet that attempts to download and execute files from a malicious website. The malicious applet works in conjunction with other exploits such as Exploit:Java/CVE-2010-0094 and Exploit:Java/CVE-2008-5353, both of which exploit a vulnerability in the Java Runtime Environment (JRE). Successful exploitation of the affected computer allows attackers to bypass applet sandbox restrictions and gain read and write access to the local file system. 
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.AB is a trojan Java applet that could allow the downloading and execution of arbitrary malicious files.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.EM is the detection for an Java applet that is part of an exploit of Java Virtual Machine, and can be used to download and execute arbitrary files from a malicious website.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.AK is a trojan Java applet that could allow the downloading and execution of arbitrary malicious files.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.JP is the detection for an malicious Java class applet component that exploits a vulnerability described in CVE-2010-0840. Successful exploitation may lead to the downloading and execution of arbitrary files.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.JS is a detection for an obfuscated Java applet that attempts to download and execute arbitrary files from a remote host. It often works in conjunction with Exploit:Java/CVE-2010-0094, which attempts to exploit a vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23.
 
This vulnerability allows an unsigned Java applet to gain elevated privileges and potentially have unrestricted access to a host system, outside its "sand box" environment.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.KR is a trojan Java applet that could allow the downloading and execution of arbitrary malicious files.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.G is the detection for a malicious Java applet trojan that exploits a vulnerability described in CVE-2010-0840. Successful exploitation may lead to the downloading and execution of arbitrary files.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Java/OpenConnection.M is a  Java applet that attempts to download and execute files from a malicious web site. It often works in conjunction with Java/Classloader and Java/Bytverify that exploit a vulnerability in the ByteCode verifier component of the Microsoft VM, as described and fixed in MS03-011.
Alert level: severe