W32/Tibs.KD!tr

description-logoAnalysis

  • Drops the following files:
    • alsys.exe
    • SERVICES.EXE
  • Adds the following registry:
    • key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    • value:
    • data: undefinedSystemundefined\alsys.exe
    • key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    • value:
    • data: undefinedSystemundefined\alsys.exe
  • Modifies the following registry:
    • key: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
    • value: Start
    • data: 4
  • Email Propagation:
    • Email format:

      • Subject:
      • I Think of You
        
      • Attachments: one of the following:
        • flash postcard.exe
        • greeting card.exe
        • greeting postcard.exe
        • postcard.exe

    recommended-action-logoRecommended Action

      FortiGate Systems
    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

    Telemetry logoTelemetry

    Detection Availability

    FortiClient
    Extreme
    FortiMail
    Extreme
    FortiSandbox
    Extreme
    FortiWeb
    Extreme
    Web Application Firewall
    Extreme
    FortiIsolator
    Extreme
    FortiDeceptor
    Extreme
    FortiEDR