Infection Channel: Downloaded from the Internet
This malware exploits a vulnerability in CVE-2012-1875, which is addressed in MS12-037 bulletin.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

Once this malware exploits the vulnerability, it downloads malicious files.
This Trojan executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
File size: Varies
File type: HTML, HTM
Initial samples received date: 13 Jun 2012
Payload: Downloads files
Arrival Details
This Trojan may be downloaded from the following remote sites:
- http://{BLOCKED}.{BLOCKED}.241.239/css.htm
Download Routine
This Trojan accesses the following websites to download files:
- http://{BLOCKED}.{BLOCKED}.241.239/javaw.exe - detected by Trend Micro as BKDR_AGENT.BCSG
- http://{BLOCKED}.{BLOCKED}.236.143/english/cala.exe - detected by Trend Micro as TROJ_AGENT.BCSH
It takes advantage of the following software vulnerabilities to download possibly malicious files:
It saves the files it downloads using the following names:
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
Connect with us on
| | | |