Download.ject, also known as Toofer, Scob, JS.Scob.Trojan, and JS.Toofeer, was a 2004 malware campaign affecting Microsoft Windows environments that compromised insecure websites running Microsoft Internet Information Services (IIS), particularly IIS 5.0 on Windows 2000. On compromised servers, it appended malicious JavaScript to all pages served by the site. When a user visited an infected page with Internet Explorer on Windows, the injected script executed automatically and exploited Internet Explorer cross-domain vulnerabilities together with the ADODB.Stream ActiveX control to write files to disk and install additional malware. Reported payloads included backdoor and keylogging programs, and the activity was described as capable of stealing sensitive financial information. The campaign notably combined server-side compromise with client-side browser exploitation and reportedly affected thousands of websites, including financial and corporate sites. The widespread activity was first noticed on 2004-06-23, with some reporting suggesting it may have begun earlier, and was disrupted on 2004-06-25 when the Russian-hosted server distributing the payload was shut down. High-confidence indicators and traits mentioned in the content include malicious JavaScript injected into IIS-hosted web pages, use of IE cross-domain flaws, abuse of the ADODB.Stream control, and retrieval of payloads from a server in Russia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Functional exploit code is publicly available, and there are reports of incidents involving this vulnerability (Scob, Download.Ject, Toofeer, Berbew). Any program that hosts the WebBrowser ActiveX control or used the IE HTML rendering engine (MSHTML) may be affected by this vulnerability. ... Apply the patch (867801) referenced in Microsoft Security Bulletin MS04-025.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
2004 Bagle Beast Download.ject NetSky Sasser Mydoom
See also ... Download.ject
A server-side web compromise malware that injects malicious JavaScript into IIS-hosted web pages, causing Internet Explorer users who visit the site to download and install backdoor and keylogging malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.