W32/Fareit.CGB!tr
Analysis
W32/Fareit.CGB!tr is a generic detection for a trojan. Since this is a generic detection, malware that are detected as W32/Fareit.CGB!tr may have varying behaviour.
Below are examples of some of these behaviours:
- It drops the following files:
- undefinedAppDataundefined\ASound.exe : This file is a copy of the malware.
- undefinedStartUpundefined\ABsound.exe : This file is a copy of the malware.
- undefinedAppDataundefined\[Random]\[Random].exe : Depending on the original malware, this file can be either the moved file of undefinedSystemRootundefined\system32\svchost.exe (Service host) from the affected host or another copy of the malware itself.
- undefinedAppDataundefined\[Random]\[Random].hdb : This is a four-byte non-malicious data file or another copy of the malware itself.
- The following registry modifications are applied:
- HKCU\Software\Microsoft\Windows\Currentversion\Run
- [OriginalFilename].exe = undefinedAppdataundefined\ASound.exe
- HKCU\Software\Microsoft\Windows\Currentversion\Run
- It also spawns an instance of undefinedSystemRootundefined\system32\svchost.exe.
- It connects to the following remote sites
- bahru{Removed}mkediri.sch.id/temps/fre.php
- www.leyo{Removed}.com/45/Panel/five/fre.php
- onc{Removed}.info
- In some instances, this malware may delete itself after executing.
Recommended Action
- Make sure that your FortiGate/FortiClient system is using the latest AV database.
- Quarantine/delete files that are detected and replace infected files with clean backup copies.
Telemetry
Detection Availability
FortiGate | |
---|---|
Extended | |
FortiClient | |
FortiMail | |
FortiSandbox | |
FortiWeb | |
Web Application Firewall | |
FortiIsolator | |
FortiDeceptor | |
FortiEDR |
Version Updates
Date | Version | Detail |
---|---|---|
2021-02-16 | 84.08100 | Sig Updated |
2020-12-02 | 82.26800 | Sig Updated |
2020-11-03 | 81.56700 | Sig Updated |
2020-05-04 | 77.17300 | Sig Updated |
2019-08-20 | 71.01900 | Sig Updated |
2019-07-05 | 69.76100 | Sig Updated |
2019-03-13 | 67.02500 | Sig Updated |
2018-12-11 | 64.82100 | Sig Updated |
2018-11-15 | 64.20200 | Sig Updated |
2018-11-15 | 64.20000 | Sig Updated |