RunForestRun

Aliases: Blackhole, Sutra

First seen
2012-01-01 00:00:00
Malware type
exploit-kit
Family
Malware family
Profile updated
2026-07-07 14:34:08

Context

Active around 2012-2013, this family deployed small JavaScript snippets on infected websites to load exploit kit scripts from DGA-generated domains. It commonly used the Blackhole exploit kit and the Sutra Traffic Distribution System (TDS), which caused it to sometimes be misnamed as Blackhole or Sutra.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Runforestrun (report)
  • web.archive.org — Runforestrun And Pseudo Random Domains (report)
  • blog.malwaremustdie.org — Runforrestrun Dga Is Alive At (report)
  • github.com — Dga Research Tips.Md (report)
  • Kaspersky — 57865 (report)
  • blog.malwaremustdie.org — Fuzzy In Manual Cracking Of (report)
  • shadowserver.org — Beware The Trolls Secure Your Trackers (report)
  • malware.dontneedcoffee.com — Eyeglanceru (report)
  • stopmalvertising.com — Pseudo Random Domains (report)

External references