W32/Krap.AE!tr

description-logoAnalysis



This is a generic detection for a type of trojan downloader that uses a polymorphic custom packer.

Technical Details


  • It registers itself to run at each Windows startup by one of the following methods:
    • Creates a copy of itself to the undefinedSYSTEMundefined folder and modifies the following registry:
      • key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
      • value: Userinit
      • data: undefinedSYSTEMundefined\userinit.exe,undefinedSYSTEMundefined\[VirusCopy],

      The filename of this dropped copy may vary. An example of the filename is sdra64.exe.

    • Renames the file undefinedSYSTEMundefined\userinit.exe  to stu2.exe, then copies itself as undefinedSYSTEMundefined\userinit.exe.

  • It may delete itself from the current folder.

  • It attempts to download malicious files from predefined URLs to the undefinedTEMPundefined folder, then executes them.

  • It may create a new instance of the process undefinedSYSTEMundefined\svchost.exe  and inject malicious downloader codes into it.


recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
    FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR

Version Updates

Date Version Detail
2021-09-07 88.00941
2021-08-31 88.00773
2021-06-30 87.00279
2021-06-23 87.00122
2021-04-06 85.00256
2021-03-16 84.00752
2021-03-09 84.00585
2021-01-20 83.44200 Sig Updated
2020-12-25 82.80700 Sig Updated
2020-12-24 82.78200 Sig Added