This is the Trend Micro detection for files that contain malicious IFRAME tags.
File size: 219 bytes
File type: HTML, HTM
Memory resident: No
Initial samples received date: 23 Dec 2010
Payload: Downloads files
Arrival Details
This Trojan may be downloaded from the following remote sites:
- http://{BLOCKED}defenceforce.com/card
- http://{BLOCKED}s.com.au/card
Other Details
This is the Trend Micro detection for files that contain malicious IFRAME tags.
It does the following:
- Arrives via spammed messages containing links where this file can be downloaded:

- Once this malicious HTML page is viewed, it displays the following image:

- Redirects browsers to the following website to download a .ZIP, file which contains a malicious file detected as TSPY_ZBOT.XMAS:
- http://{BLOCKED}developersdk.com/wp-admin/includes/card.zip
Connect with us on
| | | |