MSIL/Kryptik.MVB!tr

description-logoAnalysis



MSIL/Kryptik.MVB!tr is a generic detection for a downlaoder Trojan. Since this is a generic detection, this malware may have varying behaviour.
Some of the MSIL/Kryptik.MVB!tr samples link to the Fareit (aka Pony) malware.
Below are some of the observed characteristics/behaviours:

  • This malware has been observed to attempt connection to:
    • http://juanjoserif{Removed}.com
    • http://sariraatjga{Removed}.com

  • Once connected, the malware may attempt to downlaod the following files:
    • http://juanjoserif{Removed}.com/cgi-sys/suspendedpage.cgi
    • http://juanjoserif{Removed}.com/pc/Doc.049173001517294468.jar
    • http://sariraatjga{Removed}.com/dew/fre.php

  • This malware may drop one or more of the following files:
    • %Temp%\Name of the melted file.exe : a copy of the original file
    • %AppData%\Microsoft\Windows\Start Menu\Programs\[RandomName_1].exe : a copy of the original file
    • %AppData%\Microsoft\Windows\Start Menu\Programs\Startup\[RandomName_1].[RandomName_2].lnk : a link file that directs to the previous dropped file and runs it on every start up

  • This malware may delete the original copy after execution

  • This trojan may be a Keylogger.

  • This trojan may excercise Anti-Virtual Machine techniques .


recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2021-10-12 89.05871
2021-07-31 88.00028
2019-07-09 69.85400 Sig Updated
2019-07-02 69.68600 Sig Updated
2019-05-21 68.69100 Sig Updated
2019-04-09 67.67400 Sig Updated
2019-02-26 66.66900 Sig Updated
2019-02-12 66.33300 Sig Updated
2018-10-30 63.81200 Sig Updated