HTML/Krvking.KL!tr
Analysis
- This detection is for an IFrame appended to HTML files. It directs the browser to go to the following web site:
http://www.kr{REMOVED}.com/worm.htm
This web site connects to the following web sites:
- http://www.kr{REMOVED}.com/muma.htm
This web site downloads the following file:http://www.kr{REMOVED}.com/worm.exe
It then saves this file to the Temporary folder as svch0st.exe. This file is detected as W32/Delf.OR!tr.
- http://s8{REMOVED}.com/stat.php?id=300785&web_id=300785
This web page sends information to the following web site:
http://s8{REMOVED}.com/stat.htm
The information that it sends includes the following:
- browser type
- language
- operating system
- browser version
- time
- http://www.kr{REMOVED}.com/muma.htm
Recommended Action
-
FortiGate Systems
- Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
Telemetry
Detection Availability
FortiClient | |
---|---|
Extreme | |
FortiMail | |
Extreme | |
FortiSandbox | |
Extreme | |
FortiWeb | |
Extreme | |
Web Application Firewall | |
Extreme | |
FortiIsolator | |
Extreme | |
FortiDeceptor | |
Extreme | |
FortiEDR |
Version Updates
Date | Version | Detail |
---|---|---|
2021-08-17 | 88.00437 |