Threat Database Trojans Troj/JSRedir-R

Troj/JSRedir-R

By GoldSparrow in Trojans

Troj/JSRedir-R (also known as Gumblar) is a malicious set of scripts that are embedded in .html, .php and .js files used on a website. Troj/JSRedir-R is able to load malware content from other websites without interaction of the computer user. Once a system is infected with Troj/JSRedir-R it is known to redirect a victim's computer to Google search result pages with links to malicious webpages.

Troj/JSRedir-R is able to spread through websites by theft of FTP credentials on systems belonging to webmasters. When a user visits a Troj/JSRedir-R infected site, they are also infected. In addition to being installed through malicious websites, Troj/JSRedir-R can install a backdoor that connects to an IP address of a botnet. Troj/JSRedir-R is able to spread aggressively, such as in the case of the Conficker Worm, through exploited websites. Detection and removal of Troj/JSRedir-R is difficult due to its ability to dynamically generate malicious code or scripts on various infected websites.

Trending

Most Viewed

Loading...