HTML_ROCKRU.RI
Trojan:JS/Redirector.HO (Microsoft), Trojan-Clicker.HTML.RemoteScript (v) (Sunbelt)
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be hosted on a website and run when a user accesses the said website.
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be hosted on a website and run when a user accesses the said website.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}ock.ru/kerning.js
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL.