Home / malwarePDF  

TrojanClicker:JS/Iframe.F


First posted on 16 February 2010.
Source: SecurityHome

Aliases :

TrojanClicker:JS/Iframe.F is also known as HTML/Inor (AhnLab), Trojan-Downloader.JS.Inor.a (Kaspersky), JS.Psyme.AX (VirusBuster), HTML/Framer.CP (AVG), HEUR/HTML.Malware (Avira), Trojan.Script.252764 (BitDefender), VBS.Psyme.377 (Dr.Web), Trojan-Downloader.JS.Psyme (Ikarus), JS/Wonka (McAfee), Mal/ObfJS-H (Sophos).

Explanation :

TrojanClicker:JS/Iframe.F is a detection for specially-formed obfuscated IFrame tags, which point to remote Web sites containing adware or unwanted content.
Top

TrojanClicker:JS/Iframe.F is a detection for specially-formed obfuscated IFrame tags, which point to remote Web sites containing adware or unwanted content. It requires that the user view the Web site or open the HTML page in which it is located before it can perform its malicious actions. TrojanClicker:JS/Iframe.F has been observed to redirect the browser to the following domains:

  • youdetoxtest.net
  • ad.103092804.com


  • Analysis by Tim Liu

    Last update 16 February 2010

     

    TOP