W32/FilecoderProt.F183!tr.ransom

description-logoAnalysis

W32/FilecoderProt.F183!tr.ransom is a detection for a Ransomware trojan.
Below are some of its observed characteristics/behaviours:

  • This malware may drop any of the following file(s):
    • RESTORE_FILES.txt: This text file will serve as ransom notes. It is dropped to every infected folder.
    • HOW_TO_RESTORE_YOUR_FILES.txt : This text file will serve as ransom note. It is dropped to every infected folder.

  • This malware was also observed to affect/encrypt files located on shared drive within the same subnet.

  • Affected files of this Ransomware will use the prepending filenaming format as {Originalname.Ext}.protected.

  • Affected victims of this Ransomware are redirected by the attacker via:
    • secureserver@memeware.net

  • It deletes the shadow volume copies so that the user cannot restore them.

  • Below is an illustration of the malware's Ransom notes:

    • Figure 1: Ransom notes.


    • Figure 2 Ransom notes.




recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2019-03-29 67.41100 Sig Added
2019-03-13 67.02500 Sig Updated
2019-01-01 65.32400 Sig Updated
2018-12-28 65.22800 Sig Updated
2018-12-25 65.15600 Sig Updated
2018-12-22 65.08400 Sig Updated