MSIL/FilecoderTeiv.B2F3!tr.ransom

description-logoAnalysis


MSIL/FilecoderTeiv.B2F3!tr.ransom is a detection for a Ransomware trojan.
Below are some of its observed characteristics/behaviours:

  • This malware displays a message prompt: “Congratulations, you've got Ransomware Nightmare!”, in Vietnamese Language.


    • Figure 1: Message Box.


    • Figure 2: Code.


  • Below is the code indicating the target folders to encrypt, which is mainly User's Video folders.


    • Figure 3: Code.


  • TBelow is the code indicating the target filetypes to encrypt..


    • Figure 4: Code.

  • Below is the list of target files:
    • .avi
    • .mp4
    • .mp3
    • .flv
    • .png
    • .jpg
    • .ico
    • .doc
    • .docx
    • .xls
    • .xlsx
    • .ppt
    • .pptx
    • .pdf
    • .zip
    • .rar
    • .7z

  • Affected files of this Ransomware will use the filenaming format {original name}.nightmare.

    • Figure 5: Code.




recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
Extreme
FortiAPS
FortiAPU
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2018-12-11 64.82100 Sig Updated
2018-12-06 64.70100 Sig Updated