Content

Exploit-TaroDrop.e

Type
Trojan
SubType
Exploit
Discovery Date
08/22/2008
Length
Varies
Minimum DAT
5368 (08/22/2008)
Updated DAT
5404 (10/13/2008)
Minimum Engine
5.2.00
Description Added
08/22/2008
Description Modified
08/26/2008 12:25 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

Upon launching the document, it exploits a 0-day vulnerability in Ichitaro and executes an embedded executable. The following file is installed when the document is opened:

  • %Windr%\winnet.dll

The file is detected as BackDoor-DRZ trojan.

Symptoms

  • Unexpected execution of files upon opening a JTD file.

 

Method of Infection

When the JTD file is opened, malicious code is executed automatically using a zero day vulnerability in JustSystem Ichitaro.

Removal

Variants

Variants

    N/A

All Information

Overview -

This detection covers malformed JustSystems Ichitaro Document files that attempts to exploit a 0-day vulnerability discovered August in 2008. When opened in Ichitaro, it causes a buffer overflow that can lead to arbitrary code execution in the targeted system.

Japanese users of this application may find more information on the vulnerability:
http://www.justsystems.com/jp/info/pd8002.html (Japanese)

Characteristics

Characteristics -

Upon launching the document, it exploits a 0-day vulnerability in Ichitaro and executes an embedded executable. The following file is installed when the document is opened:

  • %Windr%\winnet.dll

The file is detected as BackDoor-DRZ trojan.

Symptoms

Symptoms -

  • Unexpected execution of files upon opening a JTD file.

 

Method of Infection

Method of Infection -

When the JTD file is opened, malicious code is executed automatically using a zero day vulnerability in JustSystem Ichitaro.

Removal -

Removal -

Variants

Variants -

    N/A