W32/VBKrypt.MBW!tr

description-logoAnalysis


  • Creates another process instance of itself, injects malicious codes into it, and executes it.

  • Creates a copy of itself to the System folder and then registers itself to run at each Windows startup by adding an entry with a random name to the following registry subkey:
    • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

  • Attempts to download and execute malicious files.


recommended-action-logoRecommended Action

FortiGate Systems

  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
Extreme
FortiAPS
FortiAPU
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2020-12-08 82.40700 Sig Updated
2020-03-04 75.73100 Sig Added
2019-10-22 72.51600 Sig Updated