JS_IFRAME.BSF
October 09, 2012
PLATFORM:
Windows 2000, Windows XP, Windows Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may be hosted on a website and run when a user accesses the said website.
TECHNICAL DETAILS
File Size:
2,323 bytes
File Type:
JS
Initial Samples Received Date:
01 Jul 2012
Arrival Details
This Trojan may be hosted on a website and run when a user accesses the said website.
NOTES:
Once an unsuspecting user visits an affected web page, this JAVA script launches a hidden IFRAME that connects to the following URL:
- http://{BLOCKED}fdpojuasfn.ru:8080/images/aublbzdni.php
As a result, routines of the downloaded scripts may also be exhibited on the affected system.