W32/Zbot.FG!tr

description-logoAnalysis


W32/Zbot.FG!tr is classified as a Trojan. Trojans have capabilities such as remote access connection handling, performing Denial of Service (DoS) or Distributed DoS (DDoS) attacks, capturing keyboard input, deleting files or objects, or terminating processes.

  • It drops the following files:
    • undefinedSYSTEMundefined\lowsec\
    • undefinedSYSTEMundefined\lowsec\local.ds
    • undefinedSYSTEMundefined\lowsec\user.ds
    • undefinedSYSTEMundefined\lowsec\user.ds.lll
    • undefinedSYSTEMundefined\sdra64.exe
  • Attempts to terminate the firewall or other security applications, including antivirus monitors.

  • It modifies the following registry:
  • To automatically execute the file sdra64.exe  whenever Windows starts:
    • key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    • value: Userinit
    • data: undefinedSYSTEMundefined\sdra64.exe
    To terminate the Windows firewall service:
    • key: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\
    • value: EnableFirewall
    • data: 0
  • It tries to access the following URL:
    • grafjasqq.[removed]

    recommended-action-logoRecommended Action

      FortiGate Systems
    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
      FortiClient Systems
    • Quarantine/delete files that are detected and replace infected files with clean backup copies.

    Telemetry logoTelemetry

    Detection Availability

    FortiGate
    FortiClient
    FortiAPS
    FortiAPU
    FortiMail
    FortiSandbox
    FortiWeb
    Web Application Firewall
    FortiIsolator
    FortiDeceptor
    FortiEDR

    Version Updates

    Date Version Detail
    2023-02-16 91.00655
    2023-02-16 91.00640
    2023-02-14 91.00577
    2022-08-16 90.05126
    2022-06-16 90.03315
    2022-03-24 90.00763
    2021-04-20 85.00593
    2021-02-04 83.78200 Sig Updated
    2021-01-19 83.40900 Sig Updated
    2021-01-12 83.24200 Sig Updated