W32/Sober.G@mm

description-logoAnalysis

Variant detection added into v4.587 AV db update.
This 32-bit models itself after previous variants, by sending itself to email addresses found on the infected system. This variant has a size greater than 48,864 bytes -- the virus contains appended garbage characters in an effort to foil attempts to identify the threat using MD5 or CRC32 checksum methods.

recommended-action-logoRecommended Action

  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option
  • Alternatively, this virus can be blocked by FortiGate units by enabling blocking of file attachments with ZIP, .COM, .EXE, .BAT, .PIF or .SCR extensions; using the FortiGate manager, enable blocking of these extensions using SMTP, IMAP or POP3 services

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR