Home / malwarePDF  

Trojan:JS/BlacoleRef.G


First posted on 22 November 2011.
Source: SecurityHome

Aliases :

There are no other names known for Trojan:JS/BlacoleRef.G.

Explanation :

Trojan:JS/BlacoleRef.G is a JavaScript trojan that redirects the browser to a malicious website that contains an instance of the "Blackhole" exploit kit. The "Backhole" exploit kit may exploit vulnerabilities in certain software that may be installed the computer. If exploitation is successful, it could lead to the download and execution of arbitrary files.


Top

Trojan:JS/BlacoleRef.G is a JavaScript trojan that redirects the browser to a malicious website that contains an instance of the "Blackhole" exploit kit. The "Backhole" exploit kit may exploit vulnerabilities in certain software that may be installed the computer. If exploitation is successful, it could lead to the download and execution of arbitrary files.

An attacker may inject a client-side script, detected as Trojan:JS/BlacoleRef.G, into a vulnerable website, which then executes when a user visits the compromised page.

Some of the URLs that Trojan:JS/BlacoleRef.G is known to redirect the browser to are:

  • mobil<removed>sica.cz.cc
  • tolfr<removed>.in
  • haire<removed>ncer.cz.cc
  • westd<removed>onf.net




Analysis by Horea Coroiu

Last update 22 November 2011

 

TOP