Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Threats » W32/Stration family

Overview

Threat Risk MEDIUM MEDIUM
Destructivity NONE NONE
Payload
Detection files published
Description created 25 Sep 2006 11:59:00
Description updated 25 Sep 2006 11:59:00
Malware type WORM
Alias Email-Worm.Win32.Warezov; W32/Spamta.worm
Spreading mechanism EMAIL
Summary None

W32/Stration family

Spreading

These worms spread as an email attachment, and often use advanced social engineering in order to get the user to click on the attachment. Latter variants usually masquerade as security updates from Microsoft.
When executed, the worms will normally show a Notepad window with garbage characters. After this they will install themselves in the startup keys in the registry, so that they are automatically run by next startup. They will now search through local files for email addresses they can send themselves to.

Payload Details

n/a

Analysis

n/a

Removal

Detection for the first variant of this series was added to the Lumension Virus Control defs August 21st 2006. Latter variants are added continuously, as needed.


Last Updated: 12 Nov 2015 11:06:11