W32/LegMir!tr.pws
Analysis
W32/LegMir!tr.pws - 06-10-09
More Info:
- key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- value: Shell
- data: Explorer.exe undefinedWINDOWSundefined\SVCHOST.exe
- key: HKLM\SoftWare\Microsoft\Windows\CurrentVersion\Run
- value: SVCHOST.exe
- data: undefinedWINDOWSundefined\SVCHOST.exe
Telemetry
Detection Availability
FortiGate | |
---|---|
Extended | |
FortiClient | |
FortiMail | |
FortiSandbox | |
FortiWeb | |
Web Application Firewall | |
FortiIsolator | |
FortiDeceptor | |
FortiEDR |