Home Malware Programs Trojans Troj/Agent-XES

Troj/Agent-XES

Posted: July 30, 2012

Threat Metric

Threat Level: 10/10
Infected PCs: 749
First Seen: July 30, 2012
Last Seen: November 15, 2024
OS(es) Affected: Windows

Troj/Agent-XES is a Trojan that propagates via a spam Blackhole malware campaign on Twitter. Spam messages on Twitter that distribute Troj/Agent-XES use the wording of 'It's you on photo?' and 'It's about you?'. An instance of the deceptive tweets is '@[Username] It's you on photo? [Domain]/#[Username].html'. Dangerous links on Twitter declare that you are pictured in an online photo. The accounts that are distributing the fake messages have either been corrupted by web attackers or have been generated with the goal to distribute malicious links. The malware infection at the end of the link is found as Troj/JSRedir-HY. The script reroutes to an IP address that itself reroutes to a .CU.CC domain, to run an executable code, which is found as Troj/Agent-XES, and finally divert to a .SU domain that incorporates the Blackhole exploit kit.

Loading...