W32/Stration.GM!tr
Analysis
drops a copy as "s.exe" downloaded by the mass mailer "nt.exe" which is another variant of Stration that is already caught
Telemetry
Detection Availability
FortiClient | |
---|---|
Extreme | |
FortiMail | |
Extreme | |
FortiSandbox | |
Extreme | |
FortiWeb | |
Extreme | |
Web Application Firewall | |
Extreme | |
FortiIsolator | |
Extreme | |
FortiDeceptor | |
Extreme | |
FortiEDR |