W32/Wauchos.AF!tr.dldr

description-logoAnalysis


W32/Wauchos.AF!tr.dldr is a generic detection for a type of trojan that drops other malware onto the compromised computer. Since this is a generic detection, files that are detected as W32/Wauchos.AF!tr.dldr may have varying behavior.
Below are examples of some of these behavior:

  • The malware applies autostart registry modifications to be able to start itself automatically.

  • It creates a new subfolder in the user's Application Data folder using a randomized folder name. It then drops another malware detected as W32/Tinba.BA!tr into this folder. The file name of this malware is also randomized.

  • It modifies the following security-related Windows registry settings in order to evade detection:
    • HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
      HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
      • HideSCAHealth = 0

    • HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
      • EnableLUA = 0

    • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
      • ShowSuperHidden = 0
      • Hidden = 2

  • It has been observed to perform a DNS query on the site d{Removed}sdk3d111.ru.

recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR

Version Updates

Date Version Detail
2023-08-01 91.05634
2023-06-08 91.04013
2023-04-25 91.02686
2023-03-18 91.01552
2023-01-31 91.00154
2022-12-23 90.08982
2022-07-26 90.04496
2022-06-21 90.03462
2022-03-22 90.00711
2022-01-14 89.08696