Content

Exploit-TaroDrop.g

Type
Trojan
SubType
Exploit
Discovery Date
03/12/2009
Length
Varies
Minimum DAT
5551 (03/12/2009)
Updated DAT
5853 (01/06/2010)
Minimum Engine
5.2.00
Description Added
03/12/2009
Description Modified
03/15/2009 11:18 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

Upon launching the document, it exploits a vulnerability in Ichitaro and executes an embedded executable .

The following file is installed when the document is opened:

  • %Windir%\System32\beer80.exe (Generic Dropper trojan)

This dropper drops following files:

Symptoms

Unexpected execution of files upon opening a JTD file.

Method of Infection

When the JTD file is opened, malicious code is executed automatically using a 0 day vulnerability in JustSystem Ichitaro.

Removal

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

A zero day vulnerability has been discovered in the wild with the JustSystem Ichitaro program using the "JTD" extension. Exploit-TaroDrop.g is a trojan that is delivered via a specially crafted Ichitaro document. Ichitaro is a Japanese word processing application provided by JustSystem. When successful,  it will drop and execute a malicious Win32 executable embedded inside the document.

A patch for this vulnerability has been published by vendor. Japanese users of this application may find more information on the vulnerability and its patch at:

http://www.justsystems.com/jp/info/js09001.html (in Japanese)

Characteristics

Characteristics -

Upon launching the document, it exploits a vulnerability in Ichitaro and executes an embedded executable .

The following file is installed when the document is opened:

  • %Windir%\System32\beer80.exe (Generic Dropper trojan)

This dropper drops following files:

Symptoms

Symptoms -

Unexpected execution of files upon opening a JTD file.

Method of Infection

Method of Infection -

When the JTD file is opened, malicious code is executed automatically using a 0 day vulnerability in JustSystem Ichitaro.

Removal -

Removal -

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A