It exploits the following vulnerability in certain versions of Microsoft Office and Microsoft Works to allow the execution of malicious code:
Vulnerability in Microsoft Word Could Allow Remote Code Execution
It contains an embedded MFC executable which is detected by Trend Micro as TSPY_ONLINEG.UBG. If the vulnerability is successfully exploited, the said file is executed.
Technical details can be found at this Trend Micro page.
Loading Comments...