W32/GenKryptik.BQOS!tr.ransom

description-logoAnalysis



W32/GenKryptik.BQOS!tr.ransom is a generic detection for a Ransomware GandCrab trojan. Since this is a generic detection, this malware may have varying behaviour.
Below are some of its observed characteristics/behaviours:

  • This malware may drop any of the following file(s):
    • %AppData%\microsoft\[Random].exe : This file is detected as W32/GenKryptik.BQOS!tr.ransom.
    • crab-decrypt.txt : This file will serve as ransom notes.
    • gdcb-decrypt.txt : This file will serve as ransom notes.

  • This malware may connect to any of the following remote sites(s):
    • dns{Removed}.soprodns.ru
    • dns{Removed}.soprodns.ru
    • 6{Removed}.171.248.178
    • ns{Removed}.virmach.ru
    • ns{Removed}.virmach.ru

  • Affected files of this Ransomware will use the filenaming format [OriginalFileName].[Ext].gdcb or [OriginalFileName].[Ext].crab .

  • This malware may apply any of the following registry modification(s):
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Runonce
        [Random] = %AppData%\microsoft\[Random].exe
      Entries made by executable programs are deleted after being processed.



recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
FortiClient
FortiAPS
FortiAPU
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2019-12-04 73.54800 Sig Updated
2019-08-30 71.24300 Sig Updated
2019-05-03 68.25000 Sig Added
2019-05-03 68.24700 Sig Updated