Once a malware successfully exploits the vulnerability, it causes certain actions to be done on the system.
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
File size: 306,230 bytes
File type: RTF
Memory resident: No
Initial samples received date: 13 Aug 2011
Payload: Opens files
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Installation
This Trojan drops the following non-malicious file:
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan takes advantage of the following software vulnerabilities to drop malicious files:
- (MS10-087) Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930)
NOTES:
Once a malware successfully exploits the said vulnerability, it causes the following actions to be done on the system:
- It drops %User Temp%\svcho.exe, which is detected as BKDR_AGENTT.S
Other Details
Upon execution, it opens the non-malicious dropped file %User Temp%\document.doc in order to hide its malicious routines from the user.
Connect with us on
| | | |