W32/Emogen.Y!tr

description-logoAnalysis


W32/Emogen.Y!tr is a generic detection for a type of trojan that uses a polymorphic custom packer. Since this is a generic detection, malware that are detected as W32/Emogen.Y!tr may have varying behavior.

  • Some examples of malware that use this packer are the following:
    • ransomware
    • downloader

  • This malware may also have the capability to connect to external servers. One sample has been observed to open a Microsoft Internet Explorer Window with the address pointing to www.1a2a3a.cn.

  • Some samples are also observed to drop files in folders such as undefinedAllUsersProfileundefined\Application Data  or undefinedProgramFilesundefined.


recommended-action-logoRecommended Action

FortiGate Systems

  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2023-10-15 91.07907
2021-11-23 89.07133
2021-10-26 89.06291
2021-09-28 89.04190
2021-09-14 89.01080
2021-09-07 88.00937
2021-08-31 88.00773
2021-08-08 88.00230
2021-07-21 87.00793
2021-07-06 87.00429