Home / malwarePDF  

Trojan.Downloader.JS.JH


First posted on 21 November 2011.
Source: BitDefender

Aliases :

Trojan.Downloader.JS.JH is also known as Trojan-Downloader.JS.Agent.bsh, JS/TrojanDownloader.Iframe.EY.gen, TR/Dldr.Agent.bsg, JS_AGENT.AGUA, HEUR/Exploit.HTML.

Explanation :

Trojan.Downloader.JS.JH it is an obfuscated JavaScript.

Files containing it are served from different websites, so they are probably created by a malware kit.

The script's "payload" differ from case to case (iframe injections, different exploits, etc.). Main purpose of the script is to install malware on the user's computer.

The script tries to protect itself from modification by using it's own code as an parameter for the decryption of the payload. It is not unusual to have multiple layers of encryption to make analysis harder and more time consuming.

Last update 21 November 2011

 

TOP

Malware :