Stration, also known as Stratio and Warezov, is a family of computer worms targeting Microsoft Windows. It disables security features on infected systems and primarily propagates via e-mail attachments, using social engineering lures that masquerade as mail-server notices claiming the recipient’s Windows system is unpatched and offering an attachment presented as a fix; the attachment is actually the worm. Later variants also spread through instant messaging and Skype chat alerts containing URLs leading to the malware. The first variant was reported in late September 2006. The family was notable for extremely rapid variant generation, reportedly peaking at up to one new variant every 30 minutes, with infected machines downloading fresh variants from remote servers controlled by the operators. This high churn complicated antivirus detection and removal because vendors required constant signature updates. In November 2006, Stration was reported as the most widespread malware infection, accounting for around one-third of reported infections, and it surpassed the Netsky.P variant as the most prevalent e-mail-borne malware. F-Secure worked with ISPs to shut down domains hosting Stration variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware 2006 ... Clickbot Stration
2006 ... Clickbot Stration
Malware 2006 Stration
2006 Agent.AWF Archiveus Clickbot Orbit Downloader Rustock Stration Zlob
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.