Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Exploit:W32/XDropper.BR


Aliases:


Exploit:W32/XDropper.BR

Malware
Exploit
W32

Summary

A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

Exploit:W32/XDropper.BR identifies malware that exploits the CVE-2007-0030 vulnerability, using a specially-crafted malicious Excel file.

This malware is also mentioned in our Weblog.


Execution

Exploit:W32/Xdropper.BR will drop the following file upon execution:

  • %temp%\svchost.exe - detected as Trojan-Dropper:W32/Agent.DJGD

The dropper will drop additional binaries that will download and executes malicious files from:

  • http://211.21.161.10/images/[..].gif
  • http://60.249.139.16/images/[..].gif
  • http://203.161.117.17/[..].gif

The URLs are dead during the investigation.







Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.