W32/DelpDldr.C!tr

description-logoAnalysis

W32/DelpDldr.C!tr is a generic detection for a trojan. Since this is a generic detection, malware that are detected as W32/DelpDldr.C!tr may have varying behaviour.
Below are some of its observed characteristics/behaviours:

  • This malware may drop any of the following file(s):
    • %WINDIR%\system32\winicons.exe : This file is a copy of the original malware itself.
    • c:\good_dogs.scr : This file is a copy of the original malware itself.
    • d:\prikol.scr : This file is a copy of the original malware itself.
    • e:\sysconf.exe : This file is a copy of the original malware itself.

  • This malware may apply any of the following registry modification(s):
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run
      • WinIcons = %WINDIR%\system32\winicons.exe
      This automatically executes the dropped file every time the infected user logs on.

  • This malware also attempts to create a process with payload of outbound connection to:
    • irc.tut.by
    • irc.mgts.by

  • This malware also sends out spam message to companies and organizations with pornography links.

recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2021-10-12 89.05871
2021-07-31 88.00024
2021-04-27 85.00761
2021-02-09 83.90700 Sig Updated
2020-06-30 78.54400 Sig Updated
2020-04-28 77.03500 Sig Updated
2020-04-02 76.41300 Sig Updated
2020-03-04 75.72300 Sig Updated
2019-12-19 73.91100 Sig Updated
2019-09-05 71.39200 Sig Updated