Home Malware Programs Trojans TrojanDownloader:JS/Nemucod.L

TrojanDownloader:JS/Nemucod.L

Posted: April 6, 2015

Threat Metric

Threat Level: 8/10
Infected PCs: 23
First Seen: April 6, 2015
Last Seen: March 4, 2019
OS(es) Affected: Windows

TrojanDownloader:JS/Nemucod.L is a high-level threat that enters unnoticed and may have disastrous consequences. The malware is a new variant of TrojanDownloader:JS/Nemucod.H and works the same way. As a typical stealthy threat, TrojanDownloader:JS/Nemucod.L relies on drive-by downloads for its distribution. The malware may also be sent directly to the victim as a contaminated e-mail attachment. After it reaches the system, it tries to block the security features that can reveal or disable it. The cyber criminals behind TrojanDownloader:JS/Nemucod.L use it in order to infect the machine with various Trojans such as PWS:Win32/Fareit and Ransom:Win32/Crowti.A. In order to achieve this, TrojanDownloader:JS/Nemucod.L establishes a connection through port 80 with remote hosts like davis1.ru. The installation of the threat leads to the creation of these files: %TEMP%\1246549.exe and %TEMP%\2865241.exe. If you can detect them, proceed with an in-depth scan with a reputable anti-malware tool before your system is heavily infected.

Loading...