VBA/Agent.GIYWJYA!tr.dldr
Analysis
VBA/Agent.GIYWJYA!tr.dldr is a generic detection for a type of macro downloader trojan that downloads other malware onto the compromised computer.
Since this is a generic detection, files that are detected as VBA/Agent.GIYWJYA!tr.dldr may have varying behavior.
Below are examples of some of these behavior:
- It downloads the following files:
- %Desktop%/[Random].exe : This file is detected as W32/GenKryptik.BQQU!tr.
- This malware issues a powershell command line that downloads from a remote site listed below, then drops it on the hosts, usually located in %Desktop%\[Random].exe, afterwhich it then executes it.
- hxxp://hol{Removed}.com/press
- hxxp://farmac{Removed}.co/hpz
- Below is an illustration of an infected document:
- Figure 1: Infected Document.
- Below is an illustration of an infected document:
- Figure 2: Infected Document.
- Below is an illustration of an infected document:
- Figure 3: Infected Document.
Recommended Action
- Make sure that your FortiGate/FortiClient system is using the latest AV database.
- Quarantine/delete files that are detected and replace infected files with clean backup copies.
Telemetry
Detection Availability
FortiGate | |
---|---|
FortiClient | |
FortiAPS | |
FortiAPU | |
FortiMail | |
FortiSandbox | |
FortiWeb | |
Web Application Firewall | |
FortiIsolator | |
FortiDeceptor | |
FortiEDR |