JS_IFRAME.BNP
November 07, 2012
ALIASES:
VirTool:JS/Obfuscator.Z (Microsoft), JS/Exploit-Blacole.aw (Symantec), Trojan-Downloader.JS.Iframe.cij (Kaspersky)
PLATFORM:
Windows 2000, Windows XP, Windows Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan executes when a user accesses certain websites where it is hosted.
It inserts an IFRAME tag that redirects users to certain URLs.
TECHNICAL DETAILS
File Size: 3,969 bytes
File Type: HTML, HTM
Initial Samples Received Date: 26 Oct 2011
Arrival Details
This Trojan executes when a user accesses certain websites where it is hosted.
Other Details
This Trojan inserts an IFRAME tag that redirects users to the following URLs:
- http://{BLOCKED}nesw.biz/in.cgi?2