Concrete signature match: Trojan - Appears legitimate but performs malicious actions for JavaScript platform, family Sonbokli
Trojan:JS/Sonbokli.A!cl is a malicious JavaScript downloader. It is typically encountered on compromised websites or through malicious advertising and is used to download and install other malware onto the user's system.
Relevant strings associated with this threat: - |#d1e49aac-8f56-4280-b9ba-993a6d77406c (NID) - }#d1e49aac-8f56-4280-b9ba-993a6d77406c (NID) - &|#b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 (NID) - &}#b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 (NID) - y*|#56a863a9-875e-4185-98a7-b882c64b5ce5 (NID) - y*}#56a863a9-875e-4185-98a7-b882c64b5ce5 (NID) - C|#be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 (NID) - C}#be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 (NID) - L|#3b576869-a4ec-4529-8536-b80a7769e899 (NID) - L}#3b576869-a4ec-4529-8536-b80a7769e899 (NID) - |#5beb7efe-fd9a-4556-801d-275e5ffc04cc (NID) - }#5beb7efe-fd9a-4556-801d-275e5ffc04cc (NID) - |#01443614-cd74-433a-b99e-2ecdc07bfc25 (NID) - }#01443614-cd74-433a-b99e-2ecdc07bfc25 (NID) - |#d3e037e1-3eb8-44c8-a917-57927947596d (NID) - }#d3e037e1-3eb8-44c8-a917-57927947596d (NID) - |#7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c (NID) - }#7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c (NID) - |#92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b (NID) - }#92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b (NID)
3bb4bdcadd94783497e174bb1a753ac4819721b1f83495c1f4884e202353338cdf0c1509903666df5d067f689b2c1b52b56488568a4def25b656a2e2d2b87f1c116056be6f10cc39aa302db3b2f1fb0b83ed63b36d790fdeb6f38b7697a82d97978337c1d9884abaf3dffaf9b4f701c8319ac3503954bbb0051741fc1743f4033077001145281f55a792789b3426ac3b45f7c83aa315bdd9f9a5b8fbcc3ffaa2Ensure Windows Defender has removed the threat and run a full system scan with updated definitions. Clear all browser caches and temporary internet files. Investigate for signs of further compromise, such as unusual network traffic or newly installed programs.