W32/Stration.E0A0@mm

description-logoAnalysis

  • Drops the following files:
    • SQHOST.EXE
    • E1.DLL
  • Adds the following registry:
    • key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    • value: sqhost
    • data: undefinedWindowsundefined\sqhost.exe s
  • Modifies the following registry:
    • key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    • value: AppInit_DLLs
    • data: e1.dll
  • Email Propagation:
    • Email format:

      • Subject:
      • postcard
        
      • Body:
      • Hi, you.ve just received a postcard. 
        For: 
        [users email address]
        
        From: 
        --- 
        Text: 
        Happy New Year! 
        Postcard: 
        Click on attachment to view a postcard. 
        ---- 
        Pre-holidays Postcards.
        
      • Attachments:
        postcard.zip
        

    recommended-action-logoRecommended Action

      FortiGate Systems
    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

    Telemetry logoTelemetry

    Detection Availability

    FortiClient
    Extreme
    FortiMail
    Extreme
    FortiSandbox
    Extreme
    FortiWeb
    Extreme
    Web Application Firewall
    Extreme
    FortiIsolator
    Extreme
    FortiDeceptor
    Extreme
    FortiEDR