W32/Chimoz.AH!tr
Analysis
- Sample is packed with ASPack.
- This trojan is downloaded by W32/Dloader.MI!tr and W32/Chimoz.AD!tr.
- Connects to the following URLs:
- http://www.wz{REMOVED}/sf/versionw.txt
- http://www.yo{REMOVED}/go_union.php
Recommended Action
-
FortiGate Systems
- Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
Telemetry
Detection Availability
FortiClient | |
---|---|
Extreme | |
FortiMail | |
Extreme | |
FortiSandbox | |
Extreme | |
FortiWeb | |
Extreme | |
Web Application Firewall | |
Extreme | |
FortiIsolator | |
Extreme | |
FortiDeceptor | |
Extreme | |
FortiEDR |