W32/Yabe.W!tr.dldr

description-logoAnalysis

  • Displays the following message:
  • Acrobat 6 - Error "Warning" 20225
    
  • Drops the following files:
    • undefinedSYSTEMundefined\iptb.exe
    • undefinedSYSTEMundefineddrivers\onud.dat
  • Tries to access the following URLs:
    • http://www.marke{REMOVED}.com/bookreview/inc/tss0.txt
    • http://www.bling{REMOVED}.com/snake1/uploads/avatars/how0.txt
    • http://www.roni{REMOVED}.net/images/cars/t0.dat
    • http://www.alexk{REMOVED}.com/images/ks.dat
    • http://testi{REMOVED}.com/editor/editk.txt
    • http://66.23{REMOVED}/~academic/img/horrk.dat
    • http://dej{REMOVED}.com/mypix/Picture0k.txt
    • http://thaila{REMOVED}.com/robotss.txt
    • http://thaila{REMOVED}.info/ro0b.txt
  • Adds the following registry:
    • key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    • value: iptb
    • data: iptb.exe

    recommended-action-logoRecommended Action

      FortiGate Systems
    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

    Telemetry logoTelemetry

    Detection Availability

    FortiClient
    Extreme
    FortiMail
    Extreme
    FortiSandbox
    Extreme
    FortiWeb
    Extreme
    Web Application Firewall
    Extreme
    FortiIsolator
    Extreme
    FortiDeceptor
    Extreme
    FortiEDR