W32/Bublik.XZ!tr

description-logoAnalysis


W32/Bublik.XZ!tr is a detection for a type of trojan that drops other malware onto the compromised computer.

  • Upon execution, it drops the following files:
    • undefinedTempundefined\selca.exe : This is a modified copy of the original malware file.
    • undefinedTempundefined\metet.exe : This file is detected as W32/Zbot.AAU!tr.

  • Users that are infected by this malware may notice HTTP connections to certain URL/IP addresses such as these:
    • thegra{Removed}904us.rar
    • renaissa{Removed}904us.rar

  • This malware also performs DNS queries on the domains of those URLs.

  • The original copy of the malware is automatically deleted after execution.

recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
    FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
Extreme
FortiAPS
FortiAPU
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2022-08-30 90.05531