JS_CERID.JS
March 17, 2014
ALIASES:
JS/Iframe.BT (Eset), JS/Kryptik.SA!tr (Fortinet) ,Trojan:JS/Iframe.AO (Microsoft) ,Trojan.Webkit!html (Symantec)
PLATFORM:
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan executes when a user accesses certain websites where it is hosted.
It inserts an IFRAME tag that redirects users to certain URLs.
TECHNICAL DETAILS
File Size:
2,353 bytes
File Type:
JS
Initial Samples Received Date:
11 Mar 2012
Arrival Details
This Trojan executes when a user accesses certain websites where it is hosted.
Other Details
This Trojan inserts an IFRAME tag that redirects users to the following URLs:
- http://{BLOCKED}tkioaojdf.ru:8080/images/aublbzdni.php