Home Malware Programs Viruses Virus:X97M/Mailcab.B

Virus:X97M/Mailcab.B

Posted: December 18, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 9
First Seen: December 18, 2012
OS(es) Affected: Windows

Virus:X97M/Mailcab.B is a virus that affects Microsoft Office Excel documents by copying itself as a macro module with the name 'ToDOLE' in all open Excel files. Virus:X97M/Mailcab.B spreads to other computer systems via emails by sending a malicoous email to the affected computer user. Once installed on the compromised PC, Virus:X97M/Mailcab.B makes system changes by dropping potentially malicious files. Virus:X97M/Mailcab.B copies itself as an .XLS file and a .VBS file in a certain location used to execute its copy so that it can run automatically every time you open Excel. The .VBS file can imitate keystrokes in an Outlook application included in the mailing routine. Virus:X97M/Mailcab.B modifies the certain registry entries that reduce macro security levels, enabling the malevolent macro code to be executed. Virus:X97M/Mailcab.B sends a copy of itself to all email addresses in a victim's Microsoft Outlook address book that are collected between the times 10:00, 11:00, 14:00 and 15:00, with the help of a .VBS file that searches for email address in a targeted Outlook inbox, and saves the addresses in a file called 'D:\Collected_Address\log.txt'. Virus:X97M/Mailcab.B creates an input box in a covered sheet in .XLS files it affects. The input box contains the message 'Warning! You are going to open a confidential file'. In addition, Virus:X97M/Mailcab.B guides the PC user to open the .VBS file able to collect email addresses, which opens the covered worksheet, which in turn executes one of its copies.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 108.54 KB (108544 bytes)
MD5: 39dc46281468f046e573aa81804db3ac
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 27, 2013

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\Software\Microsoft\Office\\Excel\Security\ "Level" = "1"HKEY_LOCAL_MACHINE\Software\Microsoft\Office\\Excel\Security\ "AccessVBOM" = "1"HKEY_CURRENT_USER\Software\Microsoft\Office\\Excel\Security\ "AccessVBOM = "1"HKEY_CURRENT_USER\Software\Microsoft\Office\\Security\ Sets value: "Level" = "1"

Additional Information

The following messages's were detected:
# Message
1To: <email address>
Subject: <attachment name>
Body:
Dear all,
<attachment name>
FYI
Attachment: <attachment name>.cab
When you open a spreadsheet, you may see the following message pop up:
"Warning! You are going to open a confidential file"

Loading...