W32/Agent.BA!tr

description-logoAnalysis

  • Copies itself to the System folder as w0rmname.exe.
  • Creates the following registry entry to automatically execute itself during startup:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
      w0rmname.exe = "undefinedSystemundefined\w0rmname.exe"

recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the 'Allow Push Update' option.
    FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR

Version Updates

Date Version Detail
2024-03-11 92.02346
2024-01-19 92.00802
2024-01-01 92.00251
2023-12-25 92.00041
2023-12-13 91.09681
2023-11-17 91.08875
2023-11-16 91.08866
2023-11-08 91.08617
2023-10-27 91.08275
2023-10-03 91.07527