Escort service infected with Troj/JSRedir-AR

Filed Under: SophosLabs

Clients of escorts and call girls are usually aware of the the risks presented from STIs. However, SophosLabs has been monitoring a different type of infection risk for clients of escorts in Indian cities.

The Troj/JSRedir-AR infection has morphed slightly:

If you look at the variable 'o[e]' (two-thirds of the way down) you will see the beginnings of an obfuscated string 'http://'. Previous versions of Troj/JSRedir-AK and Troj/JSRedir-AR have used non-alphanumeric characters to disguise the strings.

Web appliance customers browsing to these sites would have already been protected due to the adult nature of the escort sites in question.

,

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <pre> <q cite=""> <strike> <strong>