Home Malware Programs Trojans Mal/ExpJS-N

Mal/ExpJS-N

Posted: October 25, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 5
First Seen: October 25, 2011
Last Seen: January 10, 2022
OS(es) Affected: Windows

Mal/ExpJS-N is a malware threat that compromises legitimate websites. The main aim of Mal/ExpJS-N is to redirect victims to an exploit website. Mal/ExpJS-N fingerprints the PC user's browser and browser plug-ins (PDF/Java) and then tries to load relevant exploits in order to corrupt the user's PC with malware infections. You should remove Mal/ExpJS-N immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



main.php File name: main.php
Size: 49.39 KB (49396 bytes)
MD5: 82e4500799b69614863dc2905d95110b
Detection count: 24
Mime Type: unknown/php
Group: Malware file
Last Updated: January 10, 2022
main.php File name: main.php
Size: 89.44 KB (89445 bytes)
MD5: 30ebf9b1c7562d25054ee221cace630d
Detection count: 21
Mime Type: unknown/php
Group: Malware file
Last Updated: November 2, 2011
main.php File name: main.php
Size: 89.24 KB (89243 bytes)
MD5: 28432c091a5a2334b88cfc534fd15bee
Detection count: 20
Mime Type: unknown/php
Group: Malware file
Last Updated: November 2, 2011
main.php File name: main.php
Size: 44.69 KB (44691 bytes)
MD5: ef856382b687272fd3060a479d45052b
Detection count: 19
Mime Type: unknown/php
Group: Malware file
Last Updated: November 2, 2011
main.php File name: main.php
Size: 44.66 KB (44662 bytes)
MD5: 614eb00df7c1cc6f22eee8479b09398c
Detection count: 18
Mime Type: unknown/php
Group: Malware file
Last Updated: November 2, 2011
d.exe File name: d.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Additional Information

The following URL's were detected:
http://www.hanatrust.com/js/d.exe
Loading...