W97M/Thus.A

description-logoAnalysis

  • Virus consists of one macro module within the class storage
  • Virus hooks Word event handlers which prevents the opening, creating or closing of infected documents
  • Virus searches the macro storage of host files for the string

    "'Thus_001'"

    which exists in the virus body, as a means to determine if the host file is already infected

  • On December 13th of any year, virus searches for all files in all subdirectories and attempts to delete them

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR