Once a malware successfully exploits the said vulnerability, it causes certain actions to be done on the system.
File size: 150,528 bytes
File type: Other
Memory resident: No
Initial samples received date: 06 Apr 2011
Payload: Drops files
Installation
This Trojan drops the following non-malicious file:
- c:\{ascii characters}.doc
Dropping Routine
This Trojan takes advantage of the following software vulnerabilities to drop malicious files:
- RTF Stack Buffer Overflow Vulnerability (CVE-2010-3333) - http://about-threats.trendmicro.com/vulnerability.aspx?language=us&name=RTF%20Stack%20Buffer%20Overflow%20Vulnerability%20(CVE-2010-3333)
Other Details
Once a malware successfully exploits the said vulnerability, it causes the following actions to be done on the system:
- It drops the file %User Temp%\WINWORD.EXE, which is detected as BKDR_IRCBOT.KER
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
More information on this vulnerability can be found below:
Connect with us on
| | | |