W32/Stration.FR@mm

Alias/esEmail-Worm.Win32.Warezov.fh, Troj/StraDr-Gen, TROJ_STRAT.FN, W32/StraDr.FN!tr, W32/Warezov.gen4, Win32/Stration
Release DateNov 15, 2006
Detection Availability
Active DatabaseExtended Database
FortiGatelowhigh
FortiClient
FortiMailN/A
Current Antivirus Definition Database Version: 11.575
Description

Visible Symptoms

  • The file aaaaaaaaaa.exe  exists in the System folder.
  • System is also infected with W32/Stration.DT@mm and W32/Stration.DS@mm.

Detailed Analysis

  • Samples are packed with UPX.

  • Drops the file aaaaaaaaaa.exe  in the System folder, and executes it. This file is detected as W32/Stration.DT@mm. It downloads a file from a remote web site and saves it with a temporary filename into the Temporary folder. This downloaded file is detected as W32/Stration.DS@mm.
Description Last Updated Date: Mar 13, 2007
Reference: ID - 306125