This Trojan connects to websites that contain pornographic content.
This Trojan executes when a user accesses certain websites where it is hosted.
This is the Trend Micro detection for files that exhibit certain behaviors.
File size: Varies
File type: HTA
Memory resident: Yes
Initial samples received date: 10 Jul 2011
Payload: Connects to URLs/IPs
Arrival Details
This Trojan executes when a user accesses certain websites where it is hosted.
Other Details
This is the Trend Micro detection for:
- HTA (HTML Application) files that displays pornographic contents and are related to one-click billing fraud.
NOTES:
This Trojan connects to the following websites that contain pornographic content:
- http://www.{BLOCKED}ne-movies.com/regist1.php?s={parameter}&d={parameter}&f={parameter}
- http://www.{BLOCKED}ine-movies.com/vck.php?s={parameter}&d={parameter}&f={parameter}
- http://www.{BLOCKED}n-sweet.net/regist1.php?s={parameter}&d={parameter}&f={parameter}
- http://www.{BLOCKED}n-sweet.net/vck.php?s={parameter}&d={parameter}&f={parameter}
This description is based on a compiled analysis of several variants of HTML_PORNY. Note that specific data such as file names and HTTP parameters may vary for each variant.
Connect with us on
| | | |