TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
HTML_FUJACKS.E
Technical Details

File type: Script

Size of malware: Varies

Initial samples received on: Dec 21, 2006

Related toPE_FUJACKS.F-O


Payload 1: Opens URLs



Details:

This is the Trend Micro detection for an IFrame, which PE_FUJACKS.F-O appends to its infected files. The said IFrame enables the mentioned infected files to open the Web page http://www.{BLOCKED}vkr.com/worm.htm. This page, in turn, redirects the affected user to another Web page - http://www.{BLOCKED}vkr.com/muma.htm- which contains a malicious script.

Trend Micro detects the said script VBS_SMALL.EKE. The routines of this malicious VBScript may be exhibited on the affected machine.

It runs on Windows 98, ME, NT, 2000, XP, and Server 2003.

Analysis By: Julius Caezar R. Dizon

Revision History:

First pattern file version: 4.130.03
First pattern file release date: Dec 21, 2006

For additional information about this threat, see:
Overview
Solution

Search a new malware

Tell us how we did. Take our quick survey.