HTML/Krvking.KL!tr

description-logoAnalysis

  • This detection is for an IFrame appended to HTML files. It directs the browser to go to the following web site:
    http://www.kr{REMOVED}.com/worm.htm
    This web site connects to the following web sites:
    • http://www.kr{REMOVED}.com/muma.htm
      This web site downloads the following file:
      http://www.kr{REMOVED}.com/worm.exe
      It then saves this file to the Temporary folder as svch0st.exe. This file is detected as W32/Delf.OR!tr.
    • http://s8{REMOVED}.com/stat.php?id=300785&web_id=300785 This web page sends information to the following web site:
      http://s8{REMOVED}.com/stat.htm
      The information that it sends includes the following:
      • browser type
      • language
      • operating system
      • browser version
      • time


recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2021-08-17 88.00437