W32/Small.BS!tr.dldr

description-logoAnalysis


W32/Small.BS!tr.dldr is classified as a downloader Trojan. This Trojan has the capability to establish network connections and download files from a malicious website.

  • This malware attempts to connect to remote servers using specific ports, such as the following:
    • IP: 94.75{Removed} on TCP port: 80
    • IP: 202.67{Removed} on TCP port:443

  • It attempts to download executable files from web sites such as http://66.25{Removed}/go/nt.exe, then saves them into the Windows or System folders. The file is no longer available at the time of this writing

recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
    FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2022-06-21 90.03466