Home / malwarePDF  

Exploit:W32/XDropper.BR


First posted on 15 June 2010.
Source: SecurityHome

Aliases :

There are no other names known for Exploit:W32/XDropper.BR.

Explanation :

A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server.

Additional DetailsExploit:W32/XDropper.BR identifies malware that exploits the CVE-2007-0030 vulnerability, using a specially-crafted malicious Excel file.

This malware is also mentioned in our Weblog.

Execution

Exploit:W32/Xdropper.BR will drop the following file upon execution:

€ %temp%\svchost.exe - detected as Trojan-Dropper:W32/Agent.DJGD
The dropper will drop additional binaries that will download and executes malicious files from:

€ http://211.21.161.10/images/[..].gif € http://60.249.139.16/images/[..].gif € http://203.161.117.17/[..].gif
The URLs are dead during the investigation.

Last update 15 June 2010

 

TOP