W32/Androm.AF!tr.bdr

description-logoAnalysis


W32/Androm.AF!tr.bdr is a generic detection for a type of trojan. Since this is a generic detection, malware that are detected as W32/Androm.AF!tr.bdr may have varying behavior.
Below are examples of some of these behaviors:

  • It drops a copy of itself with a randomized name in the All Users' Profile folder.

  • The following registry modifications are applied:
    • HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
      • [RandomNumber] = "undefinedAllUserProfileundefined\[RandomFileName].exe"
      This runs the dropped file automatically.

    • HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
      • HideSCAHealth = 0
      This disables the Action Center notification icon for the local machine.

    • HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
      • HideSCAHealth = 0
      This disables the Action Center notification icon for the current user.

    • HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
      • EnableLUA = 0
      This disables notifications to users when programs try to make changes to the computer.

    • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
      • ShowSuperHidden = 0
      This hides protected operating system files.

    • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
      • Hidden = 2
      This hides hidden files.

  • It performs DNS queries on the following names:
    • update.microsoft.com
    • whi{Removed}.ru
    • whi{Removed}.ru/board/board.php

  • The original copy of the malware is deleted after execution.

recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
FortiClient
FortiAPS
FortiAPU
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2023-02-16 91.00655
2023-02-16 91.00640
2022-11-22 90.08067
2022-11-21 90.08043
2022-10-03 90.06554
2022-08-22 90.05306
2022-01-04 89.08396
2022-01-03 89.08373
2021-11-08 89.06684
2021-11-01 89.06481