SymbOS/Cabir.M@mm
Analysis
Extracts the following files: C:\system\RECOGS\navrecog.mdl C:\SYSTEM\SYMANTEC\NORTONANTIVIRUS\SPOOKY.APP C:\SYSTEM\SYMANTEC\NORTONANTIVIRUS\SPOOKY.RSC C:\SYSTEM\SYMANTEC\NORTONANTIVIRUS\SPOOKY.MBM C:\SYSTEM\RECOGS\NAVRECOG.MDL C:\SYSTEM\SYMANTEC\NORTONANTIVIRUS\INBOX.SIS Attempts to send itself to other Bluetooth-enabled devices that it finds.
Telemetry
Detection Availability
FortiGate | |
---|---|
FortiClient | |
FortiAPS | |
FortiAPU | |
FortiMail | |
FortiSandbox | |
FortiWeb | |
Web Application Firewall | |
FortiIsolator | |
FortiDeceptor | |
FortiEDR |