Content

Exploit-Lhaca.a

Type
Trojan
SubType
Exploit
Discovery Date
06/26/2007
Length
varies
Minimum DAT
5061 (06/26/2007)
Updated DAT
5061 (06/26/2007)
Minimum Engine
5.1.00
Description Added
06/26/2007
Description Modified
06/26/2007 12:26 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This is a generic detection that covers files attempting to exploit a vulnerability the LHA decompress tool called "+Lhaca 1.2".

Symptoms

Unexpected execution of files upon opening a lha file.

Method of Infection

When the lha file is opened with "+Lhaca 1.2", a malicious file is dropped using a zero day vulnerability in the tool.

Removal

-

Variants

Variants

    N/A

All Information

Overview -

Exploit-Lhaca.a is a trojan that takes advantage of a vulnerability in the LHA
decompress tool called "+Lhaca 1.2", and runs a malicious Win32 executable embedded inside the file.

Characteristics

Characteristics -

This is a generic detection that covers files attempting to exploit a vulnerability the LHA decompress tool called "+Lhaca 1.2".

Symptoms

Symptoms -

Unexpected execution of files upon opening a lha file.

Method of Infection

Method of Infection -

When the lha file is opened with "+Lhaca 1.2", a malicious file is dropped using a zero day vulnerability in the tool.

Removal -

Removal -

-

Variants

Variants -

    N/A