Infection Channel: Spammed via email
When executed, this malware connects to a website to access a .SWF file that exploits CVE-2012-0779 found in certain versions of Adobe Flash Player.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
File size: 114,192 bytes
File type: DOC
Initial samples received date: 07 May 2012
Payload: Executes files
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
NOTES:
Once this malicious Word document is opened, it connects to the following website to execute a malicious SWF file:
- http://www.{BLOCKED}ups.com/update/top.swf?info=789c2b2f2fd74b4ec94c2fca2f2d28d64bcecfb53204020062fe07cf&infosize=00260100
The malicious .SWF file is detected by Trend Micro as SWF_LOADER.EHL. This .SWF file extracts and executes an embedded .EXE in this Word document. As a result, malicious routines of the executed file is exhibited on the affected system.
Connect with us on
| | | |