W32/Stration.JQ@mm

description-logoAnalysis

  • Drops the following files:
    • undefineduserdirundefined\Local Setings\Temp\5.tmp
    • undefinedwindirundefined\system32\(two exe files with random name)
    • undefinedwindirundefined\system32\e1,dll
    • undefinedwindirundefined\system32\(three other dll files with random names)
    • undefinedwindirundefined\tpup.dat
    • undefinedwindirundefined\tpup.exe
    • undefinedwindirundefined\tpup.wax
    • undefinedwindirundefined\tpup.z
  • Displays the following message:
  • Unknown error.
    
  • Tries to download files from the following URLs:
    • http://www6.ertikad{REMOVED}/nt.exe
    • http://www4.ertikad{REMOVED}/lt.exe
    • http://genfushiji{REMOVED}/pr.cgi
    • http://genfushiji{REMOVED}/s.exe
  • Adds the following registry:
    • key: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    • value: tpup
    • data: tpup.exe s
    • key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
    • value: [Random]
    • data: C:\WINDOWS\System32\[Random].dll
  • Modifies the following registry:
    • key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    • value: AppInit_DLLs
    • data: e1.dll [Random].dll
  • The malware arrives as an attachment to a spammed mail using the following details:

  • Subject: any of the following:
    • postcard
    • picture
    • Mail Delivery System
    • Status
    • Error
    • Server Report
    • Good day
    • hello
    Body: any of the following
    • Hi, youve just received a postcard.
    • Happy New Year!
    • Click on attachment to view a postcard.
    • Mail transaction failed. Partial message is available.
    • The message contains Unicode characters and has been sent as a binary attachment.
    • The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment
    Attachment: any of the following
    • postcard.zip
    • message.zip
    • doc.zip
    • docs.zip
    • readme.zip
    • text.zip
    • postcard.exe
    • document.dat.scr
    • readme.txt.bat
    • file.zip
    • file.txt.pif
    • file.dat.scr
    • body.zip

    recommended-action-logoRecommended Action

      FortiGate Systems
    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

    Telemetry logoTelemetry

    Detection Availability

    FortiGate
    FortiClient
    FortiAPS
    FortiAPU
    FortiMail
    FortiSandbox
    FortiWeb
    Web Application Firewall
    FortiIsolator
    FortiDeceptor
    FortiEDR

    Version Updates

    Date Version Detail
    2020-09-08 80.22400 Sig Updated
    2020-07-11 78.81700 Sig Updated
    2020-01-23 74.74100 Sig Updated
    2019-08-27 71.17600 Sig Updated
    2019-07-26 70.26300 Sig Updated