Threat Database Trojans Troj/JSRedir-HY

Troj/JSRedir-HY

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 1
First Seen: July 30, 2012
Last Seen: April 27, 2020
OS(es) Affected: Windows

Troj/JSRedir-HY is a JavaScript Trojan that is a part of a Blackhole malware campaign, which propagates on Twitter using a pretense of 'It's you on photo?'. ALSO, versions of the malicious spam attack using the wording 'It's about you?' have been found on Twitter. An example of the dangerous tweets is '@[Username] It's you on photo? [Domain]/#[Username].html'. Hazardous links on Twitter declare that a PC users is pictured in an online photo. However, there isn't a photo of you at the end of the link. The accounts that are delivering the messages have either been hijacked by cybercrooks or have been made with the purpose of delivering dangerous links. The malware at the end of the link is recognized as Troj/JSRedir-HY. The script reroutes to an IP address that itself reroutes to a .CU.CC domain, to load an executable code, which is identified as Troj/Agent-XES, and finally divert to a .SU domain that encompasses the Blackhole exploit kit.

Trending

Most Viewed

Loading...