W32/Chimoz.AC!tr

description-logoAnalysis

  • Sample is packed with ASPack.
  • This trojan is downloaded by W32/Dloader.MI!tr.
  • Downloads the following file:
    http://www.wz{REMOVED}/sf/explore.exe
    It saves the downloaded file to the Windows folder and executes it. The downloaded file is detected as W32/Chimoz.V!tr.

recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR