W32/Agent.OH!tr

description-logoAnalysis

This is a Trojan-Dropper. Upon executing, it will drop a file in the undefinedTEMPundefined folder with a random name and execute.

recommended-action-logoRecommended Action

  • Check the main screen using the web interface to ensure the latest AV/NIDS database has been downloaded and installed. If required, enable the "Allow Push Update" option
  • Telemetry logoTelemetry

    Detection Availability

    FortiGate
    Extended
    FortiClient
    FortiMail
    FortiSandbox
    FortiWeb
    Web Application Firewall
    FortiIsolator
    FortiDeceptor
    FortiEDR

    Version Updates

    Date Version Detail
    2024-04-15 92.03395
    2024-04-15 92.03394
    2024-04-15 92.03393
    2024-04-12 92.03322
    2024-04-08 92.03186
    2024-04-08 92.03184
    2024-03-18 92.02560
    2024-03-04 92.02137
    2024-02-26 92.01932
    2024-01-12 92.00574