Today, our friends at Trend Micro blogged about a new attack vector using Microsoft Word documents. We saw this as well last week, and have written a detection for the dropped trojan.

It’s not just a “lawsuit” that’s being spammed, we also picked up another form of this attack in our honeypots over the weekend:

When you open the Word document, you see a “PDF”, but it’s actually not. It’s a JPG, which links to an executable.

In Word 2007, it’s kind of like the Amish virus: The user has to really want to get infected.

Latest VirusTotal detection here.

File COMPLA_1.EXE received on 2010.03.29 23:00:50 (UTC)
AntivirusVersionLast UpdateResult
AntiVir7.10.5.2482010.03.29TR/Dropper.Gen
Avast4.8.1351.02010.03.29Win32:Malware-gen
Avast55.0.332.02010.03.29Win32:Malware-gen
BitDefender7.22010.03.29Trojan.Downloader.JMZC
F-Secure9.0.15370.02010.03.30Trojan-Downloader:W32/Lapurd.E
GData192010.03.29Trojan.Downloader.JMZC
McAfee+Artemis59352010.03.29Artemis!60DF604563A1
McAfee-GW-Edition6.8.52010.03.29Trojan.Dropper.Gen
Microsoft1.56052010.03.30Trojan:Win32/Meredrop
Prevx3.02010.03.30High Risk Fraudulent Security Program
Sophos4.52.02010.03.30Sus/UnkPack-C
Sunbelt61142010.03.30Trojan-Downloader
Symantec20091.2.0.412010.03.30Backdoor.Trojan