|
File infectors survive in the changing threat environment by adapting to it. PE_FUJACKS, a young family of file infectors discovered in the last quarter of 2006, exemplifies this. It has taken on the traits that characterize the prevailing threat landscape: multi-component, sequential, focused, Web-based, and profit-driven. To read a comprehensive article detailing PE_FUJACKS’s routines and goals, click here: PE_FUJACKS: Jacking Up to the Times. |
This is the detection of Trend Micro for an IFrame code that PE_FUJACKS.EA-O and PE_FUJACKS.DZ-O append to their infected files.
The script code enables the said file infectors to open the Web site http://www.{BLOCKED}vebak.com/qq.htm, which redirects the affected user to a certain link where a malicious file can be downloaded. Trend Micro detects this downloaded file as PE_FUJACKS.DZ-O.