Threat Database Trojans Trojan.JS.Redirector.za

Trojan.JS.Redirector.za

By ZulaZuza in Trojans

Threat Scorecard

Ranking: 16,581
Threat Level: 90 % (High)
Infected Computers: 190
First Seen: May 20, 2013
Last Seen: July 2, 2023
OS(es) Affected: Windows

Trojan.JS.Redirector.za is a Trojan that is involved in particular web attacks launched by Brazilian cybercriminals. Trojan.JS.Redirector.za is distributed as a malevolent PAC (Proxy Auto-Config) via phishing web address. These types of malevolent scripts are used to divert the target computer user's connection to a phishing bank, credit card and other websites. After registering the web address 'java7update.com', Brazilian attackers started attacking several websites, embedding a malevolent iframe in some hijacked websites.

The iframe loads a malevolent Java applet prepared to change the proxy configuration on the Internet browser such as Internet Explorer and Firefox. The web address used in the attack refers to a file called 'update.pac'. To evade detection based on signatures, the script uses various concatenations. The purpose of Trojan.JS.Redirector.za is to divert attacked computer users to a bogus website of Mtgox.com to steal credentials, and finally, some bitcoins. This is one of the bogus websites used in the malware campaign. The malevolent PAC is recognized as Trojan.JS.Redirector.za.

File System Details

Trojan.JS.Redirector.za may create the following file(s):
# File Name Detections
1. update.pac

Trending

Most Viewed

Loading...