Encyclopedia entry
Updated:
Oct 12, 2011
| Published:
Sep 01, 2011
Aliases
IFrame.gen
(Command)
-
HTML/IFrame.sef
(Avira)
-
HTML/Iframe.B.Gen
(ESET)
-
Trojan.JS.Agent.bvy
(Kaspersky)
-
Mal/Iframe-W
(Sophos)
Alert Level
(?)
Severe
Antimalware protection details
Microsoft recommends that you download the
latest definitions
to get protected.
Detection initially created:
Definition: 1.111.1264.0 Released: Sep 01, 2011
|
Summary
Trojan:JS/BlacoleRef.C
is a malicious JavaScript that is used by an exploit kit known as "Blackhole". If the script is run within a vulnerable computer environment, it could lead the the download and execution of arbitrary files.
Symptoms
There are no common symptoms associated with this threat - links are activated within IFrames while viewing web content on maliciously modified pages. Alert notifications from installed antivirus software may be the only symptoms.
Technical Information (Analysis)
Trojan:JS/BlacoleRef.C
is a malicious JavaScript that is used by an exploit kit known as "Blackhole". If the script is run within a vulnerable computer environment, it could lead the the download and execution of arbitrary files.
Trojan:JS/BlacoleRef.C
may be encountered when visiting a compromised web page. When run, Trojan:JS/BlacoleRef.C runs obfuscated JavaScript which generates a hidden IFrame. The hidden IFrame will attempt to redirect the browser to another website that has been compromised to host the Blackhole exploit kit. If exploitation is successful, malware may be downloaded.
In the wild, Trojan:JS/BlacoleRef.C was observed to redirect browsers to domains such as the following:
-
tr5yh654wfrefg.cz.cc
-
qxhjyavy.cz.cc
-
maseoi1l4f.c0m.li
-
yrpdgiti.cz.cc
Analysis by Horea Coroiu
Prevention
Recovery
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.