Virus Characteristics
--------Updated on 14 Feb 2013-------
“JS/Exploit-Blacole.hy” is a generic detection for malicious Java code that exploits a vulnerability that allows the execution of arbitrary code
“JS/Exploit-Blacole.hy” is a generic detection for obfuscated JavaScript that points to an Iframe to a remote malicious site.
“JS/Exploit-Blacole.hy” is an obfuscated JavaScript that could be embedded into compromised websites. This Trojan will redirect the user to malicious websites and download other malwares or execute browser exploits.
Upon execution, tries to load the java script and creates a iframe to redirect the user to the following website:
- http://an[Removed]i.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c
--------Updated on 22 Feb 2013-------
Aliases
Microsoft - backdoor:win32/popwin.b
Symantec - W32.Popwin
Nod32 - Win32/TrojanDownloader.Flux trojan (variant)
Avira - TR/Spy.Gen
Kaspersky - Backdoor.Win32.Agent.bxb
“JS/Exploit-Blacole.hy” is a generic detection for malicious Java code that exploits a vulnerability that allows the execution of arbitrary code
“JS/Exploit-Blacole.hy” is a generic detection for obfuscated JavaScript that points to an Iframe to a remote malicious site.
“JS/Exploit-Blacole.hy” is an obfuscated JavaScript that could be embedded into compromised websites. This Trojan will redirect the user to malicious websites and download other malwares or execute browser exploits.
Upon execution, tries to load the java script and creates a iframe to redirect the user to the following website:
- http://an[Removed]i.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c
----- Updated on 15th Nov 2012------
“JS/Exploit-Blacole.hy” is an obfuscated JavaScript that could be embedded into compromised websites. This Trojan will redirect the user to malicious websites and download other malwares or execute browser exploits.
Upon execution, Trojan tries to load the java script and redirect the user to the following URL
hxxp://[Removed]58bce769e5c2c
---------------------------------------------------------------------------------------------------------------------------------------------------------------
“JS/Exploit-Blacole.hy” is a generic detection for malicious Java code that exploits a vulnerability that allows the execution of arbitrary code. Also it will check for the installed components such as flash plug-in and it looks for vulnerable version of flash.
“JS/Exploit-Blacole.hy” is a generic detection for obfuscated JavaScript that points to an Iframe to a remote malicious site.
“JS/Exploit-Blacole.hy” is an obfuscated JavaScript that could be embedded into compromised websites. This Trojan will redirect the user to malicious websites and download other malwares or execute browser exploits.
Upon execution, tries to load the java script and redirect the user to the following website:
KEF[Removed]IN.RU