Home Malware Programs Trojans Troj/ExpJS-IT

Troj/ExpJS-IT

Posted: May 8, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 61
First Seen: May 8, 2013
Last Seen: May 12, 2023
OS(es) Affected: Windows

Troj/ExpJS-IT is a Trojan that propagates via a hacked US Department of Labor website. A subdomain of the Department's main website, running off a separate server, what's known colloquially as a microsite, was modified to serve up a malware threat, namely Troj/ExpJS-IT. Troj/ExpJS-IT uses a malicious JavaScript file to get the vulnerable web browser to download a file called 'bookmark.png'. It seems to be an image file, but in fact it is a Windows program with the first byte changed so that it can't run by itself. The malicious JavaScript then uses the function called 'helo()' in the script above in an attempt to invoke the CVE-2012-4792 remote code execution vulnerability in Internet Explorer. The attackers hope that this will dupe the targeted web browser into jumping over its security checks to modify and run the downloaded malicious program without asking the computer user. The drive-by-download exploit script is detected as Troj/ExpJS-IT.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



bookmark.png File name: bookmark.png
Mime Type: unknown/png
Group: Malware file
Loading...