W97M/Walker.E
Analysis
- Virus consists of one macro module within the class
storage
- Virus hooks Word event handlers which prevents
the closing of infected documents
- Virus contains several blank lines of code in an
effort to trick anyone attempting to view the virus
code into thinking there is none, however scrolling
into the editor one would then see the code
- Virus contains a section of encrypted instructions,
and both an encryption routine and a decryption routine
- During infection, the virus decrypts the encrypted
section
- Infects the host file
- Encrypts the decrypted section
- During infection, the virus decrypts the encrypted
section
- Virus contains this comment line-
"'Sattelite v1.0"
Telemetry
Detection Availability
FortiGate | |
---|---|
Extreme | |
FortiClient | |
Extended | |
FortiMail | |
Extended | |
FortiSandbox | |
Extended | |
FortiWeb | |
Extended | |
Web Application Firewall | |
Extended | |
FortiIsolator | |
Extended | |
FortiDeceptor | |
Extended | |
FortiEDR |