W97M/Walker.E

description-logoAnalysis

  • Virus consists of one macro module within the class storage
  • Virus hooks Word event handlers which prevents the closing of infected documents
  • Virus contains several blank lines of code in an effort to trick anyone attempting to view the virus code into thinking there is none, however scrolling into the editor one would then see the code
  • Virus contains a section of encrypted instructions, and both an encryption routine and a decryption routine
    • During infection, the virus decrypts the encrypted section
    • Infects the host file
    • Encrypts the decrypted section
  • Virus contains this comment line-

    "'Sattelite v1.0"

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR