Analysis by: Rhena Inocencio

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: File infector

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This file infector arrives as an attachment to email messages spammed by other malware/grayware or malicious users. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size: 3,378 bytes
File Type: , VBS
Initial Samples Received Date: 03 Apr 2011

Arrival Details

This file infector arrives as an attachment to email messages spammed by other malware/grayware or malicious users.

It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

File Infection

This file infector infects the following file types:

  • Microsoft Office Word Document

NOTES:

It accesses the user's Microsoft Office Outlook application and sends mail to all e-mail addresses found in the Address Book. The said email message contains the following strings:

Subject: "Important Message From {user's e-mail username}"
Body: "Here is that document you asked for ... don't show anyone else ;-)"
Attachment: {Infected Microsoft Office Word Document}