W32/Stration.H@mm

description-logoAnalysis

Registry Information creates the entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run rsmb = "undefinedWindowsundefined\rsmb.exe s Email Propagation subject: hello body: The message contains Unicode characters and has been sent as a binary attachment. attachemnt: body.zip

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR

Version Updates

Date Version Detail
2022-07-26 90.04496
2022-05-28 90.02710