JS_NEMUCOD.SAUAX
January 30, 2017
ALIASES:
JS.Downloader (Symantec); JS/Downloader.Agent.67_K (AVG); JS/Nemucod.rp (McAfee)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 77,949 bytes
File Type: JS
Initial Samples Received Date: 26 Jan 2017
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Dropping Routine
This Trojan drops the following files:
- %Temp%\r1.log
- %Temp%\sijruhireuqfre8643jh6k3.ini
- %Temp%\{username}xmda.jpg
- %Temp%\{username}xmdb.jpg
- %Temp%\{username}xmdc.jpg
- %Temp%\{username}xmddwwg.gif
- %Temp%\guildwwg.gif
- %Temp%\{username}wwg.gif
(Note: %Temp% is the Windows temporary folder, where it usually is C:\Windows\Temp on all Windows operating system versions.)
Other Details
This Trojan connects to the following possibly malicious URL:
- https://{BLOCKED}vokaveycobexopuloqidchvmei41xupasatesucorimi.returnxyz00.returnxyz01.organiccrap.com/01/dynamikywwg.gif.zip