Infection Channel: Spammed via email, Dropped by other malware, Downloaded from the Internet
This malware exploits the vulnerability in Microsoft XML Core Services, which prompted Microsoft to release a fix tool.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It executes when a user accesses certain websites where it is hosted.
It takes advantage of software vulnerabilities to allow a remote user or malware/grayware to download files. It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL. This is the Trend Micro detection for Web pages that were compromised through the insertion of a certain IFRAME tag.
File size: 12,063 bytes
File type: HTML, HTM
Initial samples received date: 26 Jun 2012
Payload: Downloads files
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes when a user accesses certain websites where it is hosted.
Download Routine
This Trojan connects to the following website(s) to download and execute a malicious file:
- http://{BLOCKED}ia.co.in/css/css.exe - detected as BKDR_POISON.HUQA
It takes advantage of the following software vulnerabilities to allow a remote user or malware/grayware to download files:
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Other Details
Once a user visits an affected Web page, this HTML script launches a hidden IFRAME that connects to a malicious URL.
It inserts the following code:
- http://www.{BLOCKED}9.com.hk
Connect with us on
| | | |