s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.unidentified_js_002

📛 Threat Title

Malware family: Unidentified JS 002

Category: Unidentified JS 002 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.unidentified_js_002`. Printable name: Unidentified JS 002.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019. Jazi, Hossein. (2021, January 6). Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat. Retrieved March 22, 2022. Faou, M. and Boutin, J . (2017, February). Read The Manual: A Guide to the RTM Banking Trojan.

  • web:github.com

    The malware targets a wider set of JS - family files than originally documented, and has been observed inside binary assets like .woff2 font files. Counts below reflect the 2026-04-10 corpus of 1,736 unique repos.

  • web:learn.microsoft.com

    Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Unidentified JS 002 malware family including references, samples and yara signatures.

  • web:thehackernews.com

    Researchers detail JS#SMUGGLER, a multi-stage web attack using JavaScript, HTA, and PowerShell to deploy NetSupport RAT on targeted systems.

  • web:www.breachsense.com

    Malware incident response is the coordinated process of identifying, containing, eradicating, and recovering from malware infections. It includes isolating infected systems, analyzing the malware's behavior, remediating affected accounts, and implementing controls to prevent reinfection.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.cloudsek.com

    RedSun exposes a critical logic flaw in Windows Defender that allows a standard user to escalate privileges to SYSTEM without admin rights or kernel exploits. By exploiting a missing reparse point validation during file restoration, attackers can redirect Defender's write operation into System32 and execute arbitrary code. The attack is reliable, unpatched, and affects modern Windows systems ...

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

  • web:www.tenforums.com

    However, Protection History is showing one as " Remediation incomplete" after I clicked on "take action" , with status :"failed" and warnings of danger. I find Microsoft's "communication skills" ambiguous and contradictory. Another "severe threat" item, after "take action" is chosen, is shown as "Removed or restored". What does that mean?

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.