MSWord/SpamDocCrypted!tr

description-logoAnalysis

MSWord/SpamDocCrypted!tr is a detection for a malicious document trojan.
Below are some of its observed behaviours:

  • This malware has been observed to attempt download from 20{Removed}.141.59.124/azo.exe, but during the time of our tests this site appears to have been offlined.

  • The malware usually arrives via spam mail with an attached password protected 1234 Word Document, below are some of its illustrations:

    • Figure 1: Password protected document.


    • Figure 2: Infected Document.


recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2022-01-04 89.08393