Infection Channel: Downloaded from the Internet, Dropped by other malware
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
File size: 828,744 bytes
File type: PDF
Initial samples received date: 14 Feb 2013
Payload: Drops files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following component file(s):
- %AppDataLocal%\cache\LangBar32.dll - TROJ_INJECT.CPX
- %AppDataLocal%\cache\LangBar64.dll (64-bit only) - TROJ64_INJECT.CPX
(Note: %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local on Windows Vista and 7.)
It drops the following non-malicious file:
- %User Temp%\Visaform Turkey.pdf
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
It creates the following folders:
- %AppDataLocal%\cache
- %AppDataLocal%\cache\{random}
(Note: %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local on Windows Vista and 7.)
Dropping Routine
This Trojan executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
NOTES:
It takes advantage of a zero-day vulnerability in the following software to drop malicious files:
- Adobe PDF Reader 9
- Adobe PDF Reader 10
- Adobe PDF Reader 11
It opens the file, Visaform Turkey.pdf to trick users into thinking that it is a normal .PDF file.
Connect with us on
| | | |