A Christmas Malware

An e-mail containing an attachment named MERRY CHRISTMAS!.rar has been spammed through email.


An Image of the email is shown below


Upon execution it plays an swf file, MERRY CHRISTMAS!.swf which distracts users from the other file that is dropped. A file named SQLserver.exe which is detected by Trend as TROJ_AGENT.AMM.


The e-mail attachment is now detected as TROJ_SAMX.A.