Infection Channel: Via email
This Microsoft Word document malware uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed. Specifically, it makes use of North Korea rocket launch to lure users into opening itself.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
File size: 154,555 bytes
File type: RTF
Initial samples received date: 20 Apr 2012
Payload: Drops files
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Installation
This Trojan drops the following non-malicious file:
- %User Temp%\London 2012.doc
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan drops the following files:
- %System Root%\Document and Settings\All users\realupdate.exe - detected as BKDR_CYSXL.A
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It takes advantage of the following software vulnerabilities to drop malicious files:
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
NOTES:
Upon execution, it opens its dropped non-malicious file, %User Temp%\London 2012.doc, to hide its malicious routines from the user.
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.. %Temp% is the Windows Temporary folder, which is usually C:\Windows\Temp or C:\WINNT\Temp.)
Connect with us on
| | | |