Home / malware TrojanDownloader:W97M/Bartallex.B
First posted on 05 March 2015.
Source: MicrosoftAliases :
There are no other names known for TrojanDownloader:W97M/Bartallex.B.
Explanation :
Threat behavior
Installation
This threat is a malicious macro that can be embedded in a Microsoft Word file. When you open the malicious file, Microsoft Word should show you a security notification to ask whether you want to enable macros. If you enable macros, this threat will run.
We have seen this threat spread in a Word file that is attached to spam emails as a .doc file. See the spam email samples below:
The attached file has a random name, for example:
- case number.doc
- e-ticket_79010838.doc
- fax_msg896-599-5459.doc
Payload
Downloads other malware
The infected .doc file contains a malicious macro script that, when opened, can download and run other malware onto your PC.
The malware uses social engineering tactics to try to get you to enable macro scripting when you view the document, as macro scripts are usually disabled by default in Microsoft Office.
We have seen the malware uses the following fake warning in an attempt to get you to enable macros:
If macros are enabled, the malicious Visual Basic Application (VBA) macro runs when the attachment is opened. It immediately downloads other malware from a remote server. We have seen it download malware from the following servers:
- r
.com/wp-content/uploads/2011/08/license.exe - 91.
.131.73/ca/file.pif
The downloaded file is usually saved and run from %TEMP% using a random file name, for example %TEMP%\444.exe.
We have seen this threat download the following malware:
- TrojanDownloader:Win32/Chanitor.A - malware that can install Backdoor:Win32/Vawtrak.F
We have also seen this threat download a clean PNG image file and saves it with a random file name, for example %TEMP%\savepic.su\5229109.png.
Analysis by Rex Plantado
Symptoms
The following can indicate that you have this threat on your PC:
- You have received an email that looks like this:
- You have opened a Microsoft Word file similar to this:
Last update 05 March 2015