W32/Parite.B

description-logoAnalysis

  • Virus is 32bit, with a size of 177600 to 177700 bytes
  • Virus writes its code to a file in the Windows\Temp folder in order to execute and infect other files – the created file will be 176,128 bytes and have a .TMP extension
  • Virus then creates a key in the registry –

    HKEY_CURRENT_USRE\Software\Microsoft\Windows\
    CurrentVersion\Explorer\
    PINF = (HEX value representing the path and filename of the .TMP file created)

  • Virus will infect .EXE or .SCR files on the local system – the infected file will grow in size by a range of 177600 to 177700 bytes

recommended-action-logoRecommended Action

Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option

Telemetry logoTelemetry

Detection Availability

FortiGate
FortiClient
FortiAPS
FortiAPU
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2024-03-26 92.02812
2024-02-12 92.01512
2024-02-05 92.01302
2024-01-22 92.00882
2024-01-08 92.00462
2023-12-26 92.00062
2023-12-22 91.09937
2023-12-09 91.09575
2023-12-08 91.09531
2023-11-23 91.09067