W32/Stration.KR@mm

description-logoAnalysis

  • It displays the following message:
  • Unknown error
    
  • Deletes itself from the current directory.

  • Copies itself to the System folder as {RANDOM}.exe  and executes this copy.

  • Attempts to download the following file and executes it:
    http://www6.k{REMOVED}sus.com/chr/913/nt.exe
    This occurs every minute.
  • recommended-action-logoRecommended Action

      FortiGate Systems
    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

    Telemetry logoTelemetry

    Detection Availability

    FortiClient
    Extreme
    FortiMail
    Extreme
    FortiSandbox
    Extreme
    FortiWeb
    Extreme
    Web Application Firewall
    Extreme
    FortiIsolator
    Extreme
    FortiDeceptor
    Extreme
    FortiEDR