This Trojan arrives as attachment to mass-mailed email messages. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 167,148 bytes
File type: RTF
Initial samples received date: 19 Dec 2011
Arrival Details
This Trojan arrives as attachment to mass-mailed email messages.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following non-malicious file:
- %User Temp%\{malware file and extension name}
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan drops the following files:
- %User Temp%\svchost.exe - detected by Trend Micro as BKDR_PCCLIEN.BQD
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It takes advantage of the following software vulnerabilities to drop malicious files:
Other Details
More information on this vulnerability can be found below:
NOTES:
It opens the file %User Temp%\{malware file and extension name} in Microsoft Word to hide its malicious routines from the user.
Connect with us on
| | | |