1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




PFV-Exploit.D

Alias:Exploit.Win32.IMG-WMF
Size:53608
Category:Virus
Platform:Win32

Summary

PFV-Exploit.D was spammed on January the 1st 2006 with subject "Happy New Year" and body text "picture of 2006". The email contains an attachement file "HappyNewYear.jpg" which exploits the Microsoft WMF SetAbortProc vulnerability.

Additional Details

When the infected attachement is viewed on vulnerable computer, it tries to download and execute a file from web server www.ritztours.com. The file is a variant of Bifrose backdoor, detected as W32/Bifrose.KT.

Please see the following links for more details about the WMF vulnerability:

http://www.kb.cert.org/vuls/id/181038
http://www.microsoft.com/technet/security/advisory/912840.mspx
http://www.f-secure.com/weblog/


Write-up: Jarkko Turkulainen

Technical Details: Jarkko Turkulainen, January 1, 2006