PFV-Metasploit

Classification

Malware

-

W32

PFV-Metasploit

Summary

PFV-Metasploit files are WMF documents containing exploit for Windows WMF SetAbortProc flaw.

Removal

Automatic action

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

Find out more
Knowledge Base

Find the latest advice in our Community Knowledge Base.

Product Manual

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

PFV-Metasploit files are generated by the metasploit framework. These are highly variable WMF documents containing exploit for Windows WMF SetAbortProc flaw. Some charasteristics of the files are:

  • Random size, up to maximum frame size of underlying networkRandom amount of random WMF records in the beginning and in the end of documentHighly polymorphic shellcode in between the random records

The shellcode itself is highly configurable by the metasploit framework, its functionality includes running any file on the infected machine, updloading and executing additional components and running the metasploit shell ("meterpreter").

Date Created: -

Date Last Modified: -