Home Malware Programs Trojans Troj/DexFont-A

Troj/DexFont-A

Posted: November 26, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 7
First Seen: November 26, 2012
Last Seen: April 16, 2021
OS(es) Affected: Windows

Troj/DexFont-A is a Trojan, which spreads via a hacked Go Daddy website corrupting PC users with ransomware. Troj/DexFont-A is used by attackers to hijack the DNS records of Go Daddy hosted websites. Cybercriminals are exploiting DNS by hijacking the DNS records of websites, adding one or more additional subdomains with corresponding DNS entries (A records) referencing malicious IP addresses. The legitimate hostname resolves to the legitimate IP address, but the added sub-domains resolve to rogue servers. This allows attackers to use legitimate-looking URLs in their attacks, which can help to avoid security filtering and trick PC users into believing the content is safe. The rogue servers are running an exploit kit calling itself 'Cool EK', which is actually very similar to Blackhole Exploit Kit. The Russian origin of the kit is obvious from the login page for the admin panel. Computer users visiting the malicious website are hit with numerous malicious files, exploiting several vulnerabilities, in order to corrupt them with ransomware. When run, the ransomware displays the fake pop-up payment page created by Troj/DexFont-A with contents that differ depending on the country of the affected computer user.

Loading...