user@threatcheck.sh ~ threat-analysis
bash
$ analyze-threat Trojan:JS/Sonbokli.A!cl
Trojan:JS/Sonbokli.A!cl - Windows Defender threat signature analysis

Trojan:JS/Sonbokli.A!cl - Windows Defender Threat Analysis

$ cat analysis.txt
=== THREAT ANALYSIS REPORT ===
Threat Name: Trojan:JS/Sonbokli.A!cl
Classification:
Type:Trojan
Platform:JS
Family:Sonbokli
Detection Type:Concrete
Known malware family with identified signatures
Variant:A
Specific signature variant within the malware family
Suffix:!cl
Confidence:Very High
False-Positive Risk:Low

Concrete signature match: Trojan - Appears legitimate but performs malicious actions for JavaScript platform, family Sonbokli

Summary:

Trojan:JS/Sonbokli.A!cl is a malicious JavaScript downloader. It is typically encountered on compromised websites or through malicious advertising and is used to download and install other malware onto the user's system.

Severity:
High
VDM Static Detection:
Relevant strings associated with this threat:
 - |#d1e49aac-8f56-4280-b9ba-993a6d77406c (NID)
 - }#d1e49aac-8f56-4280-b9ba-993a6d77406c (NID)
 - &|#b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 (NID)
 - &}#b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 (NID)
 - y*|#56a863a9-875e-4185-98a7-b882c64b5ce5 (NID)
 - y*}#56a863a9-875e-4185-98a7-b882c64b5ce5 (NID)
 - C|#be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 (NID)
 - C}#be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 (NID)
 - L|#3b576869-a4ec-4529-8536-b80a7769e899 (NID)
 - L}#3b576869-a4ec-4529-8536-b80a7769e899 (NID)
 - |#5beb7efe-fd9a-4556-801d-275e5ffc04cc (NID)
 - }#5beb7efe-fd9a-4556-801d-275e5ffc04cc (NID)
 - |#01443614-cd74-433a-b99e-2ecdc07bfc25 (NID)
 - }#01443614-cd74-433a-b99e-2ecdc07bfc25 (NID)
 - |#d3e037e1-3eb8-44c8-a917-57927947596d (NID)
 - }#d3e037e1-3eb8-44c8-a917-57927947596d (NID)
 - |#7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c (NID)
 - }#7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c (NID)
 - |#92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b (NID)
 - }#92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b (NID)
Known malware which is associated with this threat:
Filename: LETTER OF PROTEST.js
3bb4bdcadd94783497e174bb1a753ac4819721b1f83495c1f4884e202353338c
09/12/2025
Filename: 2025-12-09-009071.js
df0c1509903666df5d067f689b2c1b52b56488568a4def25b656a2e2d2b87f1c
09/12/2025
Filename: 2025-12-09-00539.js
116056be6f10cc39aa302db3b2f1fb0b83ed63b36d790fdeb6f38b7697a82d97
09/12/2025
Filename: BSAR000393483.js
978337c1d9884abaf3dffaf9b4f701c8319ac3503954bbb0051741fc1743f403
09/12/2025
Filename: Annual_Benefits_Employee_Bonus_Package_December_2025_PayList.js
3077001145281f55a792789b3426ac3b45f7c83aa315bdd9f9a5b8fbcc3ffaa2
09/12/2025
Remediation Steps:
Ensure Windows Defender has removed the threat and run a full system scan with updated definitions. Clear all browser caches and temporary internet files. Investigate for signs of further compromise, such as unusual network traffic or newly installed programs.
=== END REPORT ===
$ reanalyze-threat
This analysis was last updated on 20/11/2025. Do you want to analyze it again?
$ ls available-commands/
user@threatcheck.sh:~$