Infection Channel: Downloaded from the Internet, Dropped by other malware
This malware takes advantage of zero-day vulnerabilities in Adobe Flash Player to drop malicious files.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 580,608 bytes
File type: DOC
Initial samples received date: 08 Feb 2013
Payload: Drops files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops and executes the following files:
- %User Temp%\abc.cfg - detected as BKDR_PLUGAX.A
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
NOTES:
It contains an embedded SWF file, detected by Trend Micro as SWF_EXPLOIT.MC, which is used for its dropping routine.
Connect with us on
| | | |