- Stration
Stration (also known as Stratio and Warezov) is a family of
computer worm s that can affectcomputer s runningMicrosoft Windows , disabling security features and propagating itself to other computers viae-mail attachment s. This family of worms is unusual in that new variants are being produced at an unprecedented rate, estimated to be up to one every 30 minutes at its peak, and downloaded from remote servers by infected machines to speed propagation.cite web |url=http://www.pcworld.com/article/id,127711/article.html |title=Tricky New Malware Challenges Security Vendors - PC World |date=2006-10-31 |last=Kirk |first=Jeremy] This makes detection and removal a particular challenge foranti-virus software vendors, because new signature files for each variant need to be issued to allow their software to detect them.Details
The first variant of the Stration family was reported in late September 2006. [cite web |url=http://smallbiz.symantec.com/security_response/writeup.jsp?docid=2006-092111-0525-99 |title=W32.Stration@mm - Symantec.com |date=2006-10-03] It was quickly discovered that the worm program, as well as propagating itself by sending out copies via e-mail, was downloading new variants from one of a number of remote servers. These variants were generated by a program on those servers under control of the worm's creator(s). Computer security firm
F-Secure has worked with ISPs to shut down domains hosting the variants of the worm. In November 2006, the Stration worm was the most widespread malware infection reported, accounting for around one-third of reported infections. [cite web |url=http://www.sophos.com/pressoffice/news/articles/2006/11/toptennov.html |title=Sophos announces top ten threats and hoaxes reported in November 2006]The Stration worms employ social engineering to infect the target machine by arriving in an e-mail masquerading as a report from a mail server informing the recipient (in somewhat broken English) that their computer is infected due to an unpatched security flaw in Windows, and offering as an attachment a purported fix, which is in fact the worm program itself. [cite web |url=http://www.sophos.com/pressoffice/news/articles/2006/09/stration-worm.html |title=Spreading Stration worm pretends to be security patch |date=2006-09-25] Some later variants of the worm spread via
instant messenger andSkype chat alerts containing a URL leading to the worm. [cite web| url=http://www.theregister.co.uk/2007/02/28/warezov_skype_im_worm/ |title=Warezov worm fiends target Skype |date=2007-02-28]Notes
Wikimedia Foundation. 2010.