When the Trojan executes, it may exploit the Microsoft Excel Unspecified Remote Code Execution Vulnerability (
BID 33870).
It then drops the following file:
%Temp%\rundll.exe (a copy of
Downloader)
The Trojan may then attempt to download more files on to the compromised computer from the following locations:
- [http://]61.59.24.55/sb.php?id=[19 RANDOM ASCII CHARACTERS]
- [http://]61.59.24.45/sb.php?id=[19 RANDOM ASCII CHARACTERS]
- [http://]61.221.40.63/sb.php?id=[19 RANDOM ASCII CHARACTERS]
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":