W32/Gimemo.AWIB!tr.ransom

description-logoAnalysis

W32/Gimemo.AWIB!tr.ransom is a generic detection for a screen locker .
Below are some of its observed characteristics/behaviours:

  • When this screen locker runs it will lock your screen showing some of the following infomation regarding to your computer:
    • Current date of your machine
    • Current time of your machine
    • Name of your machine
    • Your operating system
    • Username
    • Windows key
    • Counter

  • The malware will disconnect network connection after a while.
  • The malware restart the machine.
  • After the machine restart user will see the Fatal message:
    • FATAL: No bootable medium found! System halted.

  • Sceenshot of the screen locker:

    • Figure 1: Sceenshot of the screenlocker.

  • After the system restarts user will see the following Fatal message

    • Figure 2: Fatal message after the machine restarts.


recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
Extreme
FortiAPS
FortiAPU
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2018-11-06 63.98100 Sig Updated
2018-10-15 62.95000 Sig Updated