VBA/Agent.FRG!tr.dldr

description-logoAnalysis



VBA/Agent.FRG!tr.dldr is a generic detection for a Excel Macro Downloader Trojan. Since this is a generic detection, this malware may have varying behaviour.
Below are some of the observed characteristics/behaviours for this infection:

  • This malicious Excel document may download from comanylimiteddocum{Removed}.com/ohara.exe, afterwhich executes it. During the time of our tests the URL appears to be offlined.

  • This malware appears to have targeted Japanese users based on our obtained sample infected documents.

  • Below are illustrations of infected document(s) along with the spammed mail:

    • Figure 1: Spammed mail.


    • Figure 2: Infected document.



recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
FortiClient
FortiAPS
FortiAPU
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2023-02-27 91.00975