TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
XML_DLOADER.A
Overview

Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

Low

Description: 

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

XMS_DLOADER.A Behavior Diagram

Malware Overview

This malicious XML file may be downloaded unknowingly by a user when visiting malicious Web site(s).

It uses a specially crafted Microsoft Word document with embedded ActiveX control. This is identified by CLSID {AE24FDAE-03C6-11D1-8B76-0080C744F389}.

The said ActiveX control is used to connect to a specific Web site. The downloaded file is detected by Trend Micro as HTML_DLOADER.AS.

For additional information about this threat, see:
Solution
Technical Details

Description created: Feb. 17, 2009 12:44:22 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.