Troj/JSRedir-HY

By Domesticus in Trojans | 9 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

Troj/JSRedir-HY Description

Troj/JSRedir-HY is a JavaScript Trojan that is a part of a Blackhole malware campaign, which propagates on Twitter using a pretense of ‘It’s you on photo?’. ALSO, versions of the malicious spam attack using the wording ‘It’s about you?’ have been found on Twitter. An example of the dangerous tweets is ‘@[Username] It’s you on photo? [Domain]/#[Username].html’. Hazardous links on Twitter declare that a PC users is pictured in an online photo. However, there isn’t a photo of you at the end of the link. The accounts that are delivering the messages have either been hijacked by cybercrooks or have been made with the purpose of delivering dangerous links. The malware at the end of the link is recognized as Troj/JSRedir-HY. The script reroutes to an IP address that itself reroutes to a .CU.CC domain, to load an executable code, which is identified as Troj/Agent-XES, and finally divert to a .SU domain that encompasses the Blackhole exploit kit.

Type: Trojans

How Can You Detect Troj/JSRedir-HY?

Important Article Disclaimer

ESG Support Center

This entry was last updated on 07/30/12 and posted on 07/30/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.