(Troj/Iframe-BW, JS/IFrame.Gen, HTML/Framer)


Marius Vanta, virus researcher

Technical Description:

This is a generic detection for malware scripts affecting users who are browsing malicious websites or legitimate websites which were compromised by attackers.

The whole purpose of such a script is to redirect the users to external websites hosting content that will perform malicious downloads to the victim's computer by exploiting vulnerabilities found in browers and browser-related software.

This type of an attack is based on the iframe injection technique: the compromised websites host HTML content that is altered by addition of hidden iframes, which will load external and untrusted pages without the users' consent or notice.

Being a generic detection, Trojan.JS.PYV identifies various infections of this type. The users affected by such an attack are subject to a drive-by download. The actual downloaded content depends on the particular website which has been loaded into the iframe.