W32/Zortob.H!tr

description-logoAnalysis


W32/Zortob.H!tr is a generic detection for a type of trojan that drops other malware onto the compromised computer. Since this is a generic detection, files that are detected as W32/Zortob.H!tr may have varying behavior.
Below are examples of some of these behavior:

  • Upon execution, it drops the following copy of itself:
    • undefinedAppDataundefined\{Random}.exe

  • The following registry modification is applied:
    • key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • value: {Random}
    • data: undefinedAppDataundefined\{Random}.exe

  • During execution, it has been observed to connect to remote sites such as:
    • 162.20{Removed} on port 443
    • 218.6{Removed} on port 443
    • 109.10{Removed} on port 443

  • Some variants of this malware disguise themselves by using the Microsoft Word Document icon.

recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR

Version Updates

Date Version Detail
2023-01-10 90.09530
2022-12-06 90.08491
2022-12-05 90.08452
2022-10-01 90.06484
2022-02-22 89.09863
2021-12-11 89.07684
2020-06-30 78.54400 Sig Updated
2020-03-28 76.30600 Sig Added