Skip to main content

Trojan-Downloader:JS/Downloader.IOK

Classification

Category:

Malware

Type:

Trojan-downloader

Aliases:

  • Downloader

Summary

Trojan-Downloader:JS/Downloader.IOK is a JavaScript file that silently downloads and executes other files onto the affected machine.

Removal

Technical Details

Trojan-Downloader:JS/Downloader.IOK is distributed as a file attached to an email message. In the sample analyzed (SHA1: 9c4c9b5c9c0a67c9cec7398a0c47b37df8d92bd1), the email message used the title "My resume" while the attached file used the filename "re: Freddie Byrd.js".

The JavaScript file is obfuscated, making it impossible for the normal user to read the contents. If the user opens the attachment, the JavaScript launches and attempts to contact a remote server, which begins to silently download and execute other files on the affected machine.

Obfuscated JavaScript file

In the sample analyzed, the files downloaded were named "onewindows1s.jpg" and "twowindows2s.jpg". Despite the file names, which are indicative of image files, they are in reality executable programs.

Files downloaded by Trojan-Downloader:JS/Downloader.IOK

At the time of writing, these URLs are no longer accessible. Further analysis showed that the downloaded files were variants from the CryptoWall ransomware and Fareit password-stealing trojan families; both downloaded files are identified by generic detections.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.