hxxps://www.upload.ee/files/6688730/Script.Nemucod.7z.html
password zip : infected
js file not delete
hxxps://www.upload.ee/files/6688730/Script.Nemucod.7z.html
password zip : infected
js file not delete
Remove the link as we do not want people to download malware.
It is a javascript downloader trojan 7zip ransomeware launcher, the likes of Kovter and Locky, and often spam related.
Here a story from someone fighting that nasty (do not do this yourself at home): https://community.spiceworks.com/topic/1575845-how-to-run-7zip-in-bat-file-to-recover-files-encrypted-by-cryptolocker
polonus
Mail Shield will block these so no worries
THanks for info, TrueIndian is right, Mail Shield blocks it. Currently, this is also blocked by FileShield
Hi Sirmer and others,
I found one of this that doesn’t spread from email directly but a malicious link,see:
https://www.virustotal.com/en/url/21746490ffe6b154dd8404101bbafa343e9cb7304b060b9c13f05e03346eec77/analysis/1487581361/
Wrote some metadata to virustotal file analysis:
https://www.virustotal.com/en/file/ca59bc2a16df94b1d71d5587dbbcb672e5a91443c045ae711a0141dc8f36bb47/analysis/1487572098/
yes, there will be probably more undetected files by fileShield similar to these ones but all these files are covered by MailShield which block this attack, because it is the attack vector
True but the one I posted came from sendgrid ad redirect.
The PayLoad is not detected … yet
https://www.virustotal.com/en/file/bae249fb9a839b7e43f112efcc7b93d999318d578890e30785255c04e63ae685/analysis/1487629173/
Avast is detecting the js file now