Author Topic: New spawn of JS/Agent aka JSTrojanDownloader.HackLoad.AH trojan  (Read 2282 times)

0 Members and 1 Guest are viewing this topic.

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Various predecessors of this malware have been closed, this however was given to-day: htxp://zulu.zscaler.com/submission/show/dd0f84734642ce05094392411b2bbc74-1336420983
avast should detect this as JS:Redirector-RO [Trj]aka Blackhole aka JSTrojanDownloader.HackLoad.AH trojan
Suricata /w Emerging Threats   
Timestamp   Source IP   Destination IP   Alert
2012-05-07 22:04:16   urlQuery Client   31.210.50.42   ET CURRENT_EVENTS Possible Blackhole Landing to 8 chr folder plus index.html
the above according to IDS at: htxp://urlquery.net/report.php?id=52043

reported to virus AT avast dot com,

polonus
« Last Edit: May 07, 2012, 10:22:08 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: New spawn of JS/Agent aka JSTrojanDownloader.HackLoad.AH trojan
« Reply #1 on: May 07, 2012, 10:57:34 PM »
URLVoid 3/31: http://urlvoid.com/scan/sebatemlak.net/


I wish it stayed up a little longer. To see how the exploit looked like :-\
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Re: New spawn of JS/Agent aka JSTrojanDownloader.HackLoad.AH trojan
« Reply #2 on: May 07, 2012, 11:40:24 PM »
Hi !Donovan,

Here the analysis of an exemplar that is still alive and "kicking mischief": http://anubis.iseclab.org/?action=result&task_id=105cf5c44479650b4a59457f0df870487
Avast is detecting this malware as JS:Redirector-RO [Trj],

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!