Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

TROJ_EMBED.AA

BugsAlert Home > TROJ_EMBED.AA
 
 

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

TROJ_EMBED.AA Behavior Diagram

Malware Overview

This is the detection of Trend Micro for a specially crafted .DOC file that exploits the Microsoft Jet Database Engine vulnerability.

It usually arrives as an attachment to a email messages spammed by another malware or a malicious user.

The said vulnerability allows a malicious .DOC file to drop and execute an embedded executable file. As a result, routines of the dropped backdoor are also exhibited on the affected system.

For more information can be found in the following link:

Note that this detection is a zero-day exploit because it attacks a software vulnerability for which the vendor has not released a patch. This may pose as a dangerous situation in which a lot of computers may be affected due to the availability of the exploit code, and the fact that there is no available patch for the vulnerability.




Original Source: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_EMBED.AA

Learn more about TROJ_EMBED.AA
 
Tags: troj embed.aa

Related Items

      Bugtraq: [ MDVSA-2008:153 ] - Updated emacs packages fix vulnerability

      Vuln: Maian Script World Multiple Scripts SQL Injection and Cross-Site Scripting Vulnerabilities

      Hackers Eye .MDB

      CVE-2008-4669 (recipe_script)

      SuSE Security Update Fixes PCRE Command Execution Vulnerabilities

      CVE-2007-6329 (Office)

      MS07-055 - Critical: Vulnerability in Kodak Image Viewer Could Allow Remote Code Execution (923810) - Version:1.1

 

Pixel