HTML_IFRAME.CBB
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan may be hosted on a website and run when a user accesses the said website.
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL. This is the Trend Micro detection for Web pages that were compromised through the insertion of a certain IFRAME tag. However, as of this writing, the said sites are inaccessible.
TECHNICAL DETAILS
31,163 bytes
HTML, HTM
No
24 May 2010
Arrival Details
This Trojan may be hosted on a website and run when a user accesses the said website.
Other Details
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL.
It inserts the following code:
- http://{BLOCKED}.{BLOCKED}.27.99/ad.php
However, as of this writing, the said sites are inaccessible.