Infection Channel: Via email
This Trojan arrives as attachment to mass-mailed email messages.
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
File size: 195,248 bytes
File type: RTF
Initial samples received date: 12 Mar 2012
Payload: Drops files
Arrival Details
This Trojan arrives as attachment to mass-mailed email messages.
Installation
This Trojan drops the following non-malicious file:
- %User Temp%\TheSpeech.doc
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan drops the following files:
- %User Temp%\{random number}.tmp - detected by Trend Micro as TROJ_REDOSDR.AH
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It takes advantage of the following software vulnerabilities to drop malicious files:
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
NOTES:
It opens the dropped file %User Temp%\TheSpeech.doc in Microsoft Word to hide its malicious routines.
Connect with us on
| | | |