TROJ_ARTIEF.PI
Trojan.Mdropper (Symantec); Exploit.MSWord.CVE-2012-0158.ce (Kaspersky)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
Spammed via email
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
TECHNICAL DETAILS
352,319 bytes
RTF
No
15 Oct 2013
Drops files
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Installation
This Trojan drops and executes the following files:
- %User Temp%\Winword.exe - detected as BKDR_LIFTOH.AD
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.)
Dropping Routine
This Trojan takes advantage of the following software vulnerabilities to drop malicious files: