JS_BLACOLE.NKE
October 09, 2012
PLATFORM:
Windows 2000, Windows XP, Windows Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan executes when a user accesses certain websites where it is hosted.
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL. This is the Trend Micro detection for Web pages that were compromised through the insertion of a certain IFRAME tag.
TECHNICAL DETAILS
File Size:
30,911 bytes
File Type:
HTML, HTM
Initial Samples Received Date:
30 Sep 2011
Arrival Details
This Trojan executes when a user accesses certain websites where it is hosted.
Other Details
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL.
It inserts the following code:
- http://{BLOCKED}ki.cz.cc/count15.php