JS/PackRedir.A!tr.dldr

Alias/esJS/Redir.MR!tr
Release DateMay 19, 2009
Detection Availability
Active DatabaseExtended Database
FortiGatelowhigh
FortiClient
FortiMailN/A
Current Antivirus Definition Database Version: 11.591
Description

Visible Symptoms

  • Redirect to malicious websites.
  • Malicious files may be downloaded.

    Detailed Analysis

    This detection is for an obfuscated script that is injected to compromise websites via cross-site scripting. The malicious URL is encoded in the script.

  • When internet users visit infected websites, the injected script redirects the web browser to the malicious website that is hosting other malicious downloabable components such as PDF and SWF files. These files contain exploits which eventually downloads a malicious Win32 executable.

  • The behavior of this trojan is very similar to JS/Redir.MR!tr.
  • Description Last Updated Date: May 21, 2009
    Reference: ID - 854614