Symantec Security Response Weblog: Unknown Exploit Compromises Ichitaro

Symantec一太郎のドキュメントで発生するExploitを受信したそうです。

Symantec Security has received a sample of an Ichitaro document that contains a currently unknown exploit. This is not necessarily surprising as most software has vulnerabilities but a user who opens the document will surely be hit with a surprise.
Symantec detects the malicious document as Trojan.Tarodrop.D. When it is opened, malware is dropped onto the compromised computer, which Symantec detects as Trojan Horse. The dropped Trojan in turn drops more malware (detected as Hacktool.Keylogger) that logs keystroke and sends the stolen information to cvnxus.8800.org on TCP port 443.