I'm a Linux guy trying to understand how a Windows machine got infected with ransomware. The victim got a phishing mail with a zipfile, the zipfile contains an obfuscated javascript, the script appears to download a malicious executable using MSXML2.XMLHTTP and then somehow transfers control to it with WScript.Shell
My question is how could this work without the user seeing any alerts or confirmation boxes (maybe he did and clicked past). Would it only work in Internet Explorer, or only on an unpatched machine, or is is a more general attack that would work in Firefox or Chrome.
The javascript code is at http://andrew.triumf.ca/invoice_scan_A0FPqn.js.txt From my attempts to understand it with "node debug", the malware URLs are now offline, but it did work on Feb 25 and did infect a machine with teslacrypt.