Infection Channel: Spammed via email
This malware used a Christmas-themed exploit document to deliver its payload, BKDR_GAMFRIC.A. The backdoor (MagicFire) is rarely seen in the wild possibly because its only use in targeted attacks.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

For the related story, you may read the blog post Christmas-Themed Malware Starts to Jingle All the Way
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
File size: 75,625 bytes
File type: RTF
Initial samples received date: 06 Dec 2012
Payload: Drops files
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Installation
This Trojan drops the following files:
- %User Temp%\svchost.exe - BKDR_GAMFRIC.A
- %User Temp%\temp.doc - Normal Document
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
Dropping Routine
This Trojan takes advantage of the following software vulnerabilities to drop malicious files:
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
Connect with us on
| | | |