VBA/Agent.GIYWJYA!tr.dldr

description-logoAnalysis


VBA/Agent.GIYWJYA!tr.dldr is a generic detection for a type of macro downloader trojan that downloads other malware onto the compromised computer. Since this is a generic detection, files that are detected as VBA/Agent.GIYWJYA!tr.dldr may have varying behavior.
Below are examples of some of these behavior:

  • It downloads the following files:
    • %Desktop%/[Random].exe : This file is detected as W32/GenKryptik.BQQU!tr.

  • This malware issues a powershell command line that downloads from a remote site listed below, then drops it on the hosts, usually located in %Desktop%\[Random].exe, afterwhich it then executes it.
    • hxxp://hol{Removed}.com/press
    • hxxp://farmac{Removed}.co/hpz

  • Below is an illustration of an infected document:

    • Figure 1: Infected Document.


  • Below is an illustration of an infected document:

    • Figure 2: Infected Document.


  • Below is an illustration of an infected document:

    • Figure 3: Infected Document.



recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
FortiClient
FortiAPS
FortiAPU
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR