JS/Nemucod.CXD!tr

description-logoAnalysis


JS/Nemucod.CXD!tr is a generic detection for a type of Javascript downloader trojan that downloads and runs the Kovter malware on the compromised computer. Since this is a generic detection, files that are detected as JS/Nemucod.CXD!tr may have varying behavior.
Below are examples of some of these behavior:

  • It attempts to connect and download a file from following URL:
    • hxxp://blo{Removed}.com/wp-content/uploads/2017/03/counter/exe1.exe
    If successful, the file is saved to the Temporary folder as exe1.exe. At the time of this analysis, this file can be detected as W32/Kryptik.FROQ!tr.

recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR