W32/Bifrose.D!tr.bdr

description-logoAnalysis

W32/Bifrose.D!tr.bdr - 06-10-05


More Info:

  • It drops the following files:
    • System.exe
    • Plugin1.dat
  • Added the following registry:
    • key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    • value: system
    • data: c:\windows\system.exe
  • Added the following registry:
    • key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    • value: system
    • data: c:\windows\system32\system.exe
  • Added the following registry:
    • key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • value: system
    • data: c:\windows\system32\system.exe
  • Added the following registry:
    • key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • value: system
    • data: c:\windows\system.exe
  • Added the following registry:
    • key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}
    • value: stubpath
    • data: c:\windows\system.exe
  • Added the following registry:
    • key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}
    • value: stubpath
    • data: c:\windows\system32\system.exe

    Telemetry logoTelemetry

    Detection Availability

    FortiGate
    Extended
    FortiClient
    FortiMail
    FortiSandbox
    FortiWeb
    Web Application Firewall
    FortiIsolator
    FortiDeceptor
    FortiEDR

    Version Updates

    Date Version Detail
    2021-11-30 89.07343
    2021-09-28 89.04140
    2020-01-23 74.74100 Sig Added