W32/FilecoderProt.F183!tr.ransom
Analysis
W32/FilecoderProt.F183!tr.ransom is a detection for a Ransomware trojan.
Below are some of its observed characteristics/behaviours:
- This malware may drop any of the following file(s):
- RESTORE_FILES.txt: This text file will serve as ransom notes. It is dropped to every infected folder.
- HOW_TO_RESTORE_YOUR_FILES.txt : This text file will serve as ransom note. It is dropped to every infected folder.
- This malware was also observed to affect/encrypt files located on shared drive within the same subnet.
- Affected files of this Ransomware will use the prepending filenaming format as {Originalname.Ext}.protected.
- Affected victims of this Ransomware are redirected by the attacker via:
- secureserver@memeware.net
- It deletes the shadow volume copies so that the user cannot restore them.
- Below is an illustration of the malware's Ransom notes:
- Figure 1: Ransom notes.
- Figure 2 Ransom notes.
Recommended Action
- Make sure that your FortiGate/FortiClient system is using the latest AV database.
- Quarantine/delete files that are detected and replace infected files with clean backup copies.
Telemetry
Detection Availability
FortiGate | |
---|---|
Extended | |
FortiClient | |
FortiMail | |
FortiSandbox | |
FortiWeb | |
Web Application Firewall | |
FortiIsolator | |
FortiDeceptor | |
FortiEDR |