Threat Encyclopedia

JS_REDIR.EB

Malware type: JavaScript

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:

Reported infections:

Damage potential:

Low

Distribution potential:

Low

Description: 

This JavaScript is Trend Micro's detection for Web pages that were compromised through the insertion of a certain malicious script.

It may be hosted on a Web site and run when a user accesses the said Web site. It may be downloaded from certain remote sites.

It connects to Web site(s) to download and execute a malicious file.

It then redirects to other Web site(s).

For additional information about this threat, see:

Description created: Jul. 3, 2010 6:30:37 PM GMT -0800


TECHNICAL DETAILS


File type: Script

Memory resident:  Yes

Size of malware: Varies

Initial samples received on: Jul 2, 2010

Related toWORM_KOOBFACE.IC

Payload 1: Downloads files

Details:

 

This JavaScript is Trend Micro's detection for Web pages that were compromised through the insertion of a certain malicious script.

Arrival Details

This JavaScript may be hosted on a Web site and run when a user accesses the said Web site.

It may be downloaded from the following remote site(s):

  • http://{BLOCKED}rotherz.ca/19mai/{random name}.php

Download Routine

After redirection, this JavaScript connects to the following Web sites to download and execute other files:

  • http://{random IP}/{random characters}/setup.exe - detected by Trend Micro as WORM_KOOBFACE.IC

The said {random IP} may be the following:

  • {BLOCKED}8.54:80
  • {BLOCKED}.62.134:1002
  • {BLOCKED}.175.91:643
  • {BLOCKED}171.213:190
  • {BLOCKED}.140.168:702
  • {BLOCKED}.161.142:518
  • {BLOCKED}.38.252:845
  • {BLOCKED}.249.12:203
  • {BLOCKED}9.205:284
  • {BLOCKED}.69.1:799
  • {BLOCKED}108.196:565
  • {BLOCKED}.229.176:471
  • {BLOCKED}.31.127:627
  • {BLOCKED}.243.167:713
  • {BLOCKED}.74.225:1060
  • {BLOCKED}.70.244:956
  • {BLOCKED}112.140:549
  • {BLOCKED}217.7:518
  • {BLOCKED}20.48:409
  • {BLOCKED}115.108:1018
  • {BLOCKED}21.90:1049
  • {BLOCKED}198.84:487
  • {BLOCKED}.233.109:956
  • {BLOCKED}.64.226:362
  • {BLOCKED}.191.155:174
  • {BLOCKED}.171.54:646
  • {BLOCKED}.253.57:362
  • {BLOCKED}248.123:303
  • {BLOCKED}226.24:737
  • {BLOCKED}.156.116:377
  • {BLOCKED}.105.138:331
  • {BLOCKED}2.166.97:255
  • {BLOCKED}.149.78:362
  • {BLOCKED}.251.53:924
  • {BLOCKED}.140.65:585
  • {BLOCKED}.41.162:1034
  • {BLOCKED}.115.147:362
  • {BLOCKED}5.96.110:325
  • {BLOCKED}9.83.43:534
  • {BLOCKED}3.3.244:518
  • {BLOCKED}9.91.48:80
  • {BLOCKED}2.234.225:1020
  • {BLOCKED}0.109.163:143
  • {BLOCKED}.113.144:1049
  • {BLOCKED}.25.176:377
  • {BLOCKED}166.78:800
  • {BLOCKED}.34.33:971
  • {BLOCKED}.54.156:581
  • {BLOCKED}2.207.239:878
  • {BLOCKED}8.153.233:643
  • {BLOCKED}3.158.113:799
  • {BLOCKED}6.159.35:957
  • {BLOCKED}6.4.92:377

This {random IP} list may still change because it depends on the .PHP file that is downloaded when the URL http://{BLOCKED}rotherz.ca/19mai/ is accessed.

Other Details

This javascript then redirects to the following Web site(s):

  • http://{random IP}/go.js?{random characters}/

Affected Platforms

This javascript runs on Windows 98, ME, NT, 2000, XP, Server 2003.


Analysis By: Sabrina Sioting


SOLUTION


Minimum scan engine version needed: 8.900


Important note: The "Minimum scan engine" refers to the earliest Trend Micro scan engine version guaranteed to detect this threat. However, Trend Micro strongly recommends that you update to the latest version in order to get comprehensive protection. Download the latest scan engine here.

Solution:

For Windows ME and XP users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.

 Step 1: Close all opened browser windows 

 Step 2: Remove malware files related to JS_REDIR.EB  

 Step 3: Scan your computer with your Trend Micro product to delete files detected as JS_REDIR.EB  

*Note: If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.




Trend Micro offers best-of-breed antivirus and content-security solutions for your corporate network, small and medium business, mobile device or home PC.

Featured Stories

Connect with us on