Home / malwarePDF  

Exploit:W32/MSWord6.Gen


First posted on 23 March 2011.
Source: SecurityHome

Aliases :

There are no other names known for Exploit:W32/MSWord6.Gen.

Explanation :

The Generic Detection Exploit.msword.gen.6 identifies a Microsoft Word document that has been modified to perform an unauthorized, malicious action.

Additional DetailsExecution

Upon execution, the malware creates malicious executables in the following directories on the infected system:

  • %temp%\[random].exe
  • %windir%\system32\[name].exe
The malware also attempts to connect to the following remote sites:
  • yahoo.onedumb.com
  • yahoo.servebbs.com
  • 218.23.30.99
  • 218.20.188.170
  • googleupdate2011.dyndns.org

Last update 23 March 2011

 

TOP