NetDefend IPS
IPS Advisories
NetDefend
Anti-Virus
Anti-Virus Advisories
NetDefend Web Content Filtering
NetDefend IP Reputation
NetDefend Update Center
IPS History
May 24, 2024
May 23, 2024
May 22, 2024
May 16, 2024
May 10, 2024
Anti-Virus History
Feb 12, 2022
Jan 06, 2022
Oct 23, 2021
Aug 29, 2021
Aug 23, 2021







Home > NetDefend Live > NetDefend IPS Service
NetDefend IPS Service
Print
Advisory ID
48505
Name
MALWARE.SOCGHOLISH.ASYNCRAT.INFECTION.L
IPS Signature
Advanced IPS Signature
IPS Group
IPS / MALWARE / GENERAL
Issued
Mar 14, 2024
Description
A legitimate but compromised website infected with Parrot TDS having malicious JS is redirecting visitors to SocGholish URL with a fake browser update page which downloads zip archive and extracted JS file is ran by wscript.exe when user double clicks on it leading to web traffic for Async RAT files, Post infection, Async RAT is persistant on host and scheduled task in it runs powershell script.
Enter your details in the box below to receive an email each time we post a new issue of our newsletter.







May 26, 2024