TROJ_CVE20103333.BYZ
July 15, 2016
ALIASES:
Win32/Exploit.Agent.NPN (ESET); Exploit.RTF.Agent.q (Kaspersky); Exploit_c.ADLB (AVG); Exploit.CVE-2010-3333 (Ikarus);
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 460191 bytes
File Type: RTF
Memory Resident: Yes
Initial Samples Received Date: 08 Jul 2016
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops and executes the following files:
- {malware file path}).exe
Other Details
This Trojan connects to the following possibly malicious URL:
- www.{BLOCKED}e.pa.gov.br/themes/garland/PapiPPServer.exe