Infection Channel: Downloaded from the Internet
This malware is related to a mass compromise that leads to a series of redirections that ultimately point users to the Blackhole Exploit kit exploiting vulnerabilities cited in CVE-2010-0188 and CVE-2010-1885, respectively.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be hosted on a website and run when a user accesses the said website.
It inserts an IFRAME tag that redirects users to certain URLs. However, as of this writing, the said sites are inaccessible.
File size: 2,226 bytes
File type: Script
Initial samples received date: 17 Mar 2012
Arrival Details
This Trojan may be hosted on a website and run when a user accesses the said website.
Other Details
This Trojan inserts an IFRAME tag that redirects users to the following URLs:
- http://{BLOCKED}arkoupons.net/main.php?page=89cd1f8b9fb67fbc
However, as of this writing, the said sites are inaccessible.
Connect with us on
| | | |