Video Screencast Help

RAT W32.Extrat Activity

Created: 30 Jan 2013 • Updated: 06 Feb 2013 | 4 comments
julrendo's picture
This issue has been solved. See solution.

I can indicate the date on which the attack was detected:

RAT W32.Extrat Activity

thank you very much

Comments 4 CommentsJump to latest comment

ᗺrian's picture

Yes the definition date is available on the link you posted. Are you having an issue with it?

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

Mithun Sanghavi's picture


Yes, W32.Extrat was discovered on November 12, 2012.

W32.Extrat is a worm that spreads by copying itself to removable drives and P2P networks. It also opens a back door and steals information from the compromised computer.

Check this -

BLOG from Symantec Security Response Team

W32.Extrat: Syrian Conflict Used To Deliver Xtreme RAT

Hope that helps!!

Mithun Sanghavi
Associate Security Architect


Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.

SebastianZ's picture

The current definitions should clean up this threat, are you having any issues with the threat not being detected?