Threat Database Trojans Troj/Yolped-A

Troj/Yolped-A

By Sumo3000 in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 1
First Seen: June 27, 2012
Last Seen: April 16, 2022
OS(es) Affected: Windows

Troj/Yolped-A is a Trojan that spreads via the compromised jobs website of a major international hotel chain. A malicious script identified as Troj/JSRedir-HT is added to the compromised website. A single line of a malicious code, concealed in the website's main index.html homepage, loads an infectious script named 'icon.js', which is a Dean Edwards packed JavaScript that loads another file named 'media_view.html' within an iFrame. The file 'media_view.html' loads 'deployJava.js', which is identical to the script found on the compromised European medical website, and 'Geoffrey.swf'. 'Geoffrey.swf' is loaded via parameter 'Elderwood=' and loads a file called 'map.exe'. The file 'map.exe' found as Troj/Yolped-A ('yolped' it's 'deploy' backwards) is a data file, but it looks ambiguously like an .EXE in structure.

Trending

Most Viewed

Loading...