JS_IFRAME.BZF
Trojan:JS/Iframe.CC (Microsoft), Trojan.Webkit!html (Symantec), Mal/Iframe-W (Sophos), Trojan.JS.Obfuscator.aa (Sunbelt)
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may be hosted on a website and run when a user accesses the said website.
This is the Trend Micro detection for files that contain malicious IFRAME tags. Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL. It redirects browsers to certain sites.
TECHNICAL DETAILS
Varies
HTML, HTM
20 Aug 2012
Arrival Details
This Trojan may be hosted on a website and run when a user accesses the said website.
Other Details
This is the Trend Micro detection for files that contain malicious IFRAME tags.
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL.
It redirects browsers to the following sites:
- http://{BLOCKED}i.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c