W32/Bublik.XZ!tr
Analysis
W32/Bublik.XZ!tr is a detection for a type of trojan that drops other malware onto the compromised computer.
- Upon execution, it drops the following files:
- undefinedTempundefined\selca.exe : This is a modified copy of the original malware file.
- undefinedTempundefined\metet.exe : This file is detected as W32/Zbot.AAU!tr.
- Users that are infected by this malware may notice HTTP connections to certain URL/IP addresses such as these:
- thegra{Removed}904us.rar
- renaissa{Removed}904us.rar
- This malware also performs DNS queries on the domains of those URLs.
- The original copy of the malware is automatically deleted after execution.
Recommended Action
- FortiGate Systems
- Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
FortiClient Systems
- Quarantine/delete files that are detected and replace infected files with clean backup copies.
Telemetry
Detection Availability
FortiGate | |
---|---|
Extended | |
FortiClient | |
Extreme | |
FortiAPS | |
FortiAPU | |
FortiMail | |
Extreme | |
FortiSandbox | |
Extreme | |
FortiWeb | |
Extreme | |
Web Application Firewall | |
Extreme | |
FortiIsolator | |
Extreme | |
FortiDeceptor | |
Extreme | |
FortiEDR |
Version Updates
Date | Version | Detail |
---|---|---|
2022-08-30 | 90.05531 |