Alert level

Trojan:JS/BlacoleRef.C

(?)

Encyclopedia entry
Updated: Oct 12, 2011  |  Published: Sep 01, 2011

Aliases
  • IFrame.gen (Command)
  • HTML/IFrame.sef (Avira)
  • HTML/Iframe.B.Gen (ESET)
  • Trojan.JS.Agent.bvy (Kaspersky)
  • Mal/Iframe-W (Sophos)

Alert Level (?)
Severe

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.
Detection initially created:
Definition: 1.111.1264.0
Released: Sep 01, 2011


 

Summary

Trojan:JS/BlacoleRef.C is a malicious JavaScript that is used by an exploit kit known as "Blackhole". If the script is run within a vulnerable computer environment, it could lead the the download and execution of arbitrary files. 


 

Symptoms

There are no common symptoms associated with this threat - links are activated within IFrames while viewing web content on maliciously modified pages. Alert notifications from installed antivirus software may be the only symptoms.

 


 

Technical Information (Analysis)

Trojan:JS/BlacoleRef.C is a malicious JavaScript that is used by an exploit kit known as "Blackhole". If the script is run within a vulnerable computer environment, it could lead the the download and execution of arbitrary files.
 
Trojan:JS/BlacoleRef.C may be encountered when visiting a compromised web page. When run, Trojan:JS/BlacoleRef.C runs obfuscated JavaScript which generates a hidden IFrame. The hidden IFrame will attempt to redirect the browser to another website that has been compromised to host the Blackhole exploit kit. If exploitation is successful, malware may be downloaded.
 
In the wild, Trojan:JS/BlacoleRef.C was observed to redirect browsers to domains such as the following:
  • tr5yh654wfrefg.cz.cc
  • qxhjyavy.cz.cc
  • maseoi1l4f.c0m.li
  • yrpdgiti.cz.cc
Analysis by Horea Coroiu
 


 

Prevention



 

Recovery

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

 

Provide feedback