GRIDINSOFT HELP CENTER

Nemucod Malware: JavaScript Delivery and Cleanup

What it is

Nemucod is a trojan downloader/dropper that arrives as JavaScript or PHP and then pulls in ransomware or other malware. It’s commonly spread by email attachments and malicious links.

How it spreads – quick tour

  • Phishing emails with .js, .zip, or fake invoice attachments

  • Links to pages that serve malicious JS/PHP

  • Compromised sites that auto-download the script

What you may notice

  • Windows prompts to run “script host” or open a .js file

  • Sudden browser redirects or silent downloads

  • A second-stage payload appears - often ransomware or a stealer

Remove it now

  1. Disconnect from the internet to stop the next-stage download.

  2. Run a full anti-malware scan, reboot, then scan again.

  3. Delete suspicious .js/.vbs/.ps1 files and unknown scheduled tasks.

  4. Reset browsers and remove unknown extensions and proxy settings.

  5. From a clean device, change passwords and enable MFA.

Prevent it

  • Do not open script attachments - verify invoices out of band.

  • Keep Windows, browsers, and Office updated; block macros by default.

  • Use email and web filtering plus DNS filtering for known-bad hosts.

  • Show file extensions in Explorer so scripts are not disguised.

  • Limit script engines - prefer signed PowerShell and disable WSH if not needed.

Trace the script to its payload

Do not execute the attachment again to identify it. Preserve the message, filename, script hash, and process tree, then isolate the endpoint and scan for files downloaded after the script ran. Search the mailbox or gateway for the same lure and remove it from other recipients. Nemucod campaigns have delivered different payloads, so response should follow observed behavior rather than one family assumption. Review phishing exposure, block the source indicators, and inspect the script as malicious code only in an isolated environment.

Helpful?

Glossary (0-9, A-Z)

Still can’t find an answer?

Send us a ticket and we will get back to you.

Submit a ticket