Home Malware Programs Viruses Virus:X97M/Mailcab.B

Virus:X97M/Mailcab.B

Posted: December 18, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 9
First Seen: December 18, 2012
OS(es) Affected: Windows

Virus:X97M/Mailcab.B is a virus that affects Microsoft Office Excel documents by copying itself as a macro module with the name 'ToDOLE' in all open Excel files. Virus:X97M/Mailcab.B spreads to other computer systems via emails by sending a malicoous email to the affected computer user. Once installed on the compromised PC, Virus:X97M/Mailcab.B makes system changes by dropping potentially malicious files. Virus:X97M/Mailcab.B copies itself as an .XLS file and a .VBS file in a certain location used to execute its copy so that it can run automatically every time you open Excel. The .VBS file can imitate keystrokes in an Outlook application included in the mailing routine. Virus:X97M/Mailcab.B modifies the certain registry entries that reduce macro security levels, enabling the malevolent macro code to be executed. Virus:X97M/Mailcab.B sends a copy of itself to all email addresses in a victim's Microsoft Outlook address book that are collected between the times 10:00, 11:00, 14:00 and 15:00, with the help of a .VBS file that searches for email address in a targeted Outlook inbox, and saves the addresses in a file called 'D:\Collected_Address\log.txt'. Virus:X97M/Mailcab.B creates an input box in a covered sheet in .XLS files it affects. The input box contains the message 'Warning! You are going to open a confidential file'. In addition, Virus:X97M/Mailcab.B guides the PC user to open the .VBS file able to collect email addresses, which opens the covered worksheet, which in turn executes one of its copies.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 88.57 KB (88576 bytes)
MD5: 9960c2c27297a9f95d33f69da524b87d
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 27, 2013
file.exe File name: file.exe
Size: 305.15 KB (305152 bytes)
MD5: 23696aae95624d6b7a02380016c6b7c4
Detection count: 79
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 27, 2013
file.exe File name: file.exe
Size: 102.4 KB (102400 bytes)
MD5: 6778437cbe740361783d61a002cdc7e1
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 27, 2013
file.exe File name: file.exe
Size: 108.54 KB (108544 bytes)
MD5: 39dc46281468f046e573aa81804db3ac
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 27, 2013
file.exe File name: file.exe
Size: 140.8 KB (140800 bytes)
MD5: 82dd3d0342ef0a2239c1a1ea464abb24
Detection count: 13
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 27, 2013

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\Software\Microsoft\Office\\Excel\Security\ "Level" = "1"HKEY_LOCAL_MACHINE\Software\Microsoft\Office\\Excel\Security\ "AccessVBOM" = "1"HKEY_CURRENT_USER\Software\Microsoft\Office\\Excel\Security\ "AccessVBOM = "1"HKEY_CURRENT_USER\Software\Microsoft\Office\\Security\ Sets value: "Level" = "1"

Additional Information

The following messages's were detected:
# Message
1To: <email address>
Subject: <attachment name>
Body:
Dear all,
<attachment name>
FYI
Attachment: <attachment name>.cab
When you open a spreadsheet, you may see the following message pop up:
"Warning! You are going to open a confidential file"

Loading...