Trojan.PPDropper.B may arrive as a Powerpoint attachment in the following email:
From:
[REMOVED]@gmail.com
To:
Undisclosed-Recipient:;
Subject:
[CHINESE CHARS]
Attachment:
[CHINESE CHARS].ppt
When Trojan.PPDropper.B is executed, it performs the following actions:
- Exploits an undocumented Microsoft Powerpoint Remote Code Execution Vulnerability using a malformed string, once the Powerpoint attachment is executed.
- Drops and executes the following file which is a variant of Backdoor.Bifrose.E:
%System%\regvrt.exe
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
- Injects a malicious routine into the EXPLORER.EXE process that overwrites the malicious Powerpoint file with a new clean copy of the document.
- Displays the following title page slide in Chinese characters when the Powerpoint document is executed: