|
File infectors survive in the changing threat environment by adapting to it. PE_FUJACKS, a young family of file infectors discovered in the last quarter of 2006, exemplifies this. It has taken on the traits that characterize the prevailing threat landscape: multi-component, sequential, focused, Web-based, and profit-driven. To read a comprehensive article detailing PE_FUJACKS’s routines and goals, click here: PE_FUJACKS: Jacking Up to the Times. |
This is the Trend Micro detection for an IFrame, which PE_FUJACKS.F-O appends to its infected files. The said IFrame enables the mentioned infected files to open the Web page http://www.{BLOCKED}vkr.com/worm.htm. This page, in turn, redirects the affected user to another Web page – http://www.{BLOCKED}vkr.com/muma.htm– which contains a malicious script.
Trend Micro detects the said script VBS_SMALL.EKE. The routines of this malicious VBScript may be exhibited on the affected machine.