Infection Channel: Spammed via email
This Trojan arrives as an attachment to spammed email claiming to be from a security researcher. It drops a malicious JavaScript that drops a backdoor.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
File size: 712,890 bytes
File type: PDF
Initial samples received date: 13 Apr 2012
Payload: Drops files
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Installation
This Trojan drops the following files:
It drops the following non-malicious file:
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan takes advantage of the following software vulnerabilities to drop malicious files:
- Vulnerability in U3D component in Adobe Reader and Acrobat
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
Connect with us on
| | | |