1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Exploit:W32/XDropper.BR

Name : Exploit:W32/XDropper.BR
Category:Malware
Type:Exploit
Platform:W32

Summary

A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server.

Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.

Additional Details

Exploit:W32/XDropper.BR identifies malware that exploits the CVE-2007-0030 vulnerability, using a specially-crafted malicious Excel file.

This malware is also mentioned in our Weblog.

Execution

Exploit:W32/Xdropper.BR will drop the following file upon execution:

  •  %temp%\svchost.exe    -  detected as Trojan-Dropper:W32/Agent.DJGD

The dropper will drop additional binaries that will download and executes malicious files from:

  •  http://211.21.161.10/images/[..].gif
  • http://60.249.139.16/images/[..].gif
  • http://203.161.117.17/[..].gif

The URLs are dead during the investigation.