JS/Redir.D

By Sumo3000 in Trojans

Threat Scorecard

Popularity Rank: 10,878
Threat Level: 90 % (High)
Infected Computers: 3,354
First Seen: January 18, 2013
Last Seen: March 12, 2026
OS(es) Affected: Windows

JS/Redir.D is a JavaScript Trojan that conceals itself on the compromised PC to bypass the detection and elimination by many anti-virus programs. JS/Redir.D is distributed and installed by other security infections to perform a variety of damaging activities on the infected computer system. JS/Redir.D encompasses backdoor functionalities enabling it to open network ports for downloading and installing more malware infections onto the victimized computer system. JS/Redir.D permits attackers to obtain remote unauthorized access and control over the affected machine. JS/Redir.D steals confidential information such as passwords, credit card, bank account information and other details and sends them to a distant server.

Analysis Report

General information

Family Name: Trojan.Keygen.F
Signature status: No Signature

Known Samples

MD5: e3878a4e1babad089dc119c9e7685f18
SHA1: bb4ece37de802e4fa99abd9b62a5c88030a6b464
SHA256: A80CF7B868A7C1B359EC9771310ACC5BC004F6B48D63115DA5E912BF80B119E7
File Size: 82.94 KB, 82944 bytes
MD5: ca6507511e1db90b75c3203ad2758bf4
SHA1: e82849a8d3fff955deac3defc7fc4ee7e4935920
SHA256: 516D9C47F1E1434F0A757BCC002218E91DE61812C2996E5730AC7F1EC13463CE
File Size: 85.70 KB, 85700 bytes
MD5: c47e9952098c2eb2b7ca3db1a007278d
SHA1: 08236774adfc1bb250f123d0f9a2013fcf9e2261
SHA256: 6C21AD7407C78B7732EEDC120DAD1A6041C17BF0E2922F88AC9B1140C8097239
File Size: 293.32 KB, 293316 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft
File Version 1.00
Internal Name Win
Original Filename Win.exe
Product Name Win
Product Version 1.00

File Traits

  • HighEntropy
  • No Version Info
  • packed
  • WriteProcessMemory
  • x86

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...