JS/Redir.D

By Sumo3000 in Trojans

Threat Scorecard

Popularity Rank: 9,001
Threat Level: 90 % (High)
Infected Computers: 3,344
First Seen: January 18, 2013
Last Seen: January 13, 2026
OS(es) Affected: Windows

JS/Redir.D is a JavaScript Trojan that conceals itself on the compromised PC to bypass the detection and elimination by many anti-virus programs. JS/Redir.D is distributed and installed by other security infections to perform a variety of damaging activities on the infected computer system. JS/Redir.D encompasses backdoor functionalities enabling it to open network ports for downloading and installing more malware infections onto the victimized computer system. JS/Redir.D permits attackers to obtain remote unauthorized access and control over the affected machine. JS/Redir.D steals confidential information such as passwords, credit card, bank account information and other details and sends them to a distant server.

Analysis Report

General information

Family Name: Trojan.Keygen.F
Packers: UPX
Signature status: No Signature

Known Samples

MD5: e3878a4e1babad089dc119c9e7685f18
SHA1: bb4ece37de802e4fa99abd9b62a5c88030a6b464
SHA256: A80CF7B868A7C1B359EC9771310ACC5BC004F6B48D63115DA5E912BF80B119E7
File Size: 82.94 KB, 82944 bytes
MD5: ca6507511e1db90b75c3203ad2758bf4
SHA1: e82849a8d3fff955deac3defc7fc4ee7e4935920
SHA256: 516D9C47F1E1434F0A757BCC002218E91DE61812C2996E5730AC7F1EC13463CE
File Size: 85.70 KB, 85700 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • packed
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 273
Potentially Malicious Blocks: 26
Whitelisted Blocks: 247
Unknown Blocks: 0

Visual Map

x x x x 0 x x 0 x x 0 x x x x x x 0 x 0 x 0 0 x x x x 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 2 0 1 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 2 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 2 2 0 0 0 0 1 0 0 0 1 1 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 1 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...