TROJ_MDROPPER_WR Behavior Diagram

Malware Overview

This Trojan is dropped by other malware. It is downloaded unknowingly by a user when visiting malicious Web sites.

When executed, it exploits a certain vulnerability in Microsoft Word wherein a specially crafted document can cause the application to drop and execute an embedded file. More information about the said vulnerability can be found in the following Microsoft Web page:

When it successfully performs the said routine, this Trojan drops and executes a malicious file detected by Trend Micro as BKDR_AGENT.ADHM. As a result, routines of the dropped backdoor are also exhibited on the affected system.

Bookmark and Share