RunForestRun
Aliases: Blackhole, Sutra
- First seen
- 2012-01-01 00:00:00
- Malware type
- exploit-kit
- Family
- Malware family
- Profile updated
- 2026-07-07 14:34:08
Context
Active around 2012-2013, this family deployed small JavaScript snippets on infected websites to load exploit kit scripts from DGA-generated domains. It commonly used the Blackhole exploit kit and the Sutra Traffic Distribution System (TDS), which caused it to sometimes be misnamed as Blackhole or Sutra.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Runforestrun (report)
- web.archive.org — Runforestrun And Pseudo Random Domains (report)
- blog.malwaremustdie.org — Runforrestrun Dga Is Alive At (report)
- github.com — Dga Research Tips.Md (report)
- Kaspersky — 57865 (report)
- blog.malwaremustdie.org — Fuzzy In Manual Cracking Of (report)
- shadowserver.org — Beware The Trolls Secure Your Trackers (report)
- malware.dontneedcoffee.com — Eyeglanceru (report)
- stopmalvertising.com — Pseudo Random Domains (report)