1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Trojan-Downloader:HTML/IFrame.SV

Name : Trojan-Downloader:HTML/IFrame.SV
Detection Names : Trojan-Downloader.HTML.IFrame.sv
Category:Malware
Type:Trojan-Downloader
Platform:HTML

Summary

This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.

Additional Details

This malware will only affect a user who is browsing a malicious website, or a legitimate website which has been compromised. Unlike more straightforward trojan-downloaders, this malware does not directly download the malicious files itself, but rather redirects the user to malicious websites which perform the actual download automatically.

Upon execution, this malware uses Iframe tags to redirect the user  to the malicious websites:

http://user1.jzm018.cn/[...]/fxx.htm   - Trojan-Downloader.JS.Agent.ckl
http://jzm015.cn/[...]x.htm              - redirects to ilink.html, flink.html
http://jzm015.cn/[...]c.htm             - Trojan-Downloader.JS.Agent.ckk

These sites will then subject the visitor to a drive-by download.