W97M/Assilem.G

description-logoAnalysis

  • Virus consists of one macro module within the class storage, which is renamed from "ThisDocument" to "NoDrives"
  • Virus hooks Word event handlers which prevents the opening or closing of infected documents
  • In Spanish Windows, these menu items are disabled-
    "Tools|Securidad"
    "Tools|Macro"
    "Tools|Editor de visual basic"

recommended-action-logoRecommended Action

Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR