W32/Agent.AE78!tr

description-logoAnalysis



W32/Agent.AE78!tr is a detection for a Ransomware Gryphon downloaded by JS/Nemucod.DPD!tr.dldr.
Below are of some its observed behaviours:

  • This malware was downloaded by JS/Nemucod.DPD!tr.dldr from tolaameprt{Removed}.top/support.php?f=1.dat and will be located as undefinedTempundefined\[Random].exe and/or undefinedTempundefined\[Random].gif.

  • The Ransom notes is dropped as !## DECRYPT FILES ##!.txt

  • This malware has the capability to encrypt files located on shared folders on the same subnet.

  • This malware uses the following naming format [OriginalFileName].[Ext].[cr7icbfqm64hixta.onion].gryphon

  • Below is the malware's Ransom notes:

    • Figure 1: Ransom Notes.



recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2021-12-14 89.07763
2021-05-11 86.00097
2019-04-02 67.50600 Sig Updated