This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes the files it drops, prompting the affected system to exhibit the malicious routines they contain.
File size: 351,780 bytes
File type: RTF
Memory resident: No
Initial samples received date: 21 Mar 2012
Payload: Drops files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following non-malicious file:
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan drops the following files:
- %User Temp%\temp.exe - detected as BKDR_VISEL.FQ
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It takes advantage of the following software vulnerabilities to drop malicious files:
It executes the files it drops, prompting the affected system to exhibit the malicious routines they contain.
Connect with us on
| | | |