Threat Database Trojans Trojan.Script.Heuristic-js.iacgm

Trojan.Script.Heuristic-js.iacgm

By ZulaZuza in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 5
First Seen: October 24, 2013
Last Seen: May 22, 2023
OS(es) Affected: Windows

Trojan.Script.Heuristic-js.iacgm is a Trojan that circulates as a code in a form of a JavaScript file. This type of file commonly exists on the web server and starts once it registers a visitor. JS:Trojan.Script.AAR can be an individual file or an obfuscated script inserted into the malicious website. Trojan.Script.Heuristic-js.iacgm may create a code to have a unique signature for each website, thus, it may be difficult for anti-virus programs to find and uninstall Trojan.Script.Heuristic-js.iacgm. It is included in the header of the infected file and may pose as a part of the website. Trojan.Script.Heuristic-js.iacgm may take advantages of vulnerabilities in Adobe Reader and Flash Player. Trojan.Script.Heuristic-js.iacgm may use this weakness to distribute the code into the PC user's default web browser and control the search results on the affected PC. Trojan.Script.Heuristic-js.iacgm may reroute the PC user to a website that includes other malware threats or rogue applications. Trojan.Script.Heuristic-js.iacgm may attempt to divert computer users to doubtful websites that were designed by scammers to earn money through pay-per-click ads and associated resources. Trojan.Script.Heuristic-js.iacgm may search the targeted computer for accounts that it may use to hack a legal website. Trojan.Script.Heuristic-js.iacgm may strive to steal online accounts and FTP credentials. Trojan.Script.Heuristic-js.iacgm may store collected data into a text file and transfer it to a cybercriminal.

URLs

Trojan.Script.Heuristic-js.iacgm may call the following URLs:

aodairangdong.com
artistflower.com
autoairsystems.com
bolsaminimall.com
catch-cdn.com
corp-firewall.com
eighteas.com
emaildatastore.com
greenpowersurvey.com
himarkrealty.com
kronoemail.com
main-firewalls.com
ngnetworld.com
phattubi.com
plussolarsolutions.com
ritz-entertainment.com
saigoncitymall.com
server.evietmusic.com
viacominfosys.com
viettv24.com
vpoptv.com

1 Comment

Thank you, I've done a recent scan of a android app, an .apk file.
It's name 7zipper.
I did a scan on virustotal, it came back with some interesting findings, so I deleted the download of the 7zipper.apk
I left a comment full of info on my findings on the site that this .apk can be downloaded from.
APKMirror.
Hopefully people will clue in. Stay away from it.
Not sure if the uploader injected in there... or if it WAS there before hand.
Not sure how to find that out.
Unless I contact the holder of the original and get a copy to compare it to, I couldn't.Well, thank you and the team here, it's good to know someone out here is looking after these things.
Bye.

Trending

Most Viewed

Loading...