W32/Stration.JW@mm

description-logoAnalysis

  • It displays the following message:
  • Error: Unknow error
    
  • Drops the following files:
    • undefinedSYSTEM32undefined\usp1ds32.exe
    • undefinedSYSTEM32undefined\ipxwersv.dll
    • undefinedSYSTEM32undefined\vp31srsv.dll
    • undefinedSYSTEM32undefined\iproplus.dll
    • undefinedSYSTEM32undefined\e1.dll
  • Deletes itself from the current directory.

  • Adds the following registry:
    • key: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    • value: usp1ds32
    • data: undefinedSYSTEM32undefined\usp1ds32.exe
    • key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    • value: AppInit_DLLs
    • data: ipxwersv.dll e1.dll
  • Tries to access the following URL(s):
    • http://208.6{REMOVED}

    recommended-action-logoRecommended Action

      FortiGate Systems
    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

    Telemetry logoTelemetry

    Detection Availability

    FortiClient
    Extreme
    FortiMail
    Extreme
    FortiSandbox
    Extreme
    FortiWeb
    Extreme
    Web Application Firewall
    Extreme
    FortiIsolator
    Extreme
    FortiDeceptor
    Extreme
    FortiEDR