Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Delivery of Nodersok begins with a downloaded HTA file (although it is unclear how this file is distributed, it is likely to be via spam emails or malicious adverts), which will execute embedded JavaScript code when opened. This code will download and launch a second-stage file (either JS or XSL) containing several PowerShell commands. These commands are then used to disable security and update services, install Nodersok, and escalate its privileges. Versions of the Windivert packet capture library and the Node.exe framework are also downloaded.
Once installed, Nodersok will connect to an initial command and control (C2) server to download a JavaScript-based SOCKS proxy as well as the details of a secondary C2 server. The proxy is then deployed using Node.exe, whilst Nodersok connects to the second C2 server through Windivert.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:58 pm