The shellcode of the exploit is XOR encrypted. Below is the screenshot of the decrypted shellcode:
Microsoft already released a security advisory regarding this vulnerability. More information can be found in the following page:
Upon successful exploitation, the script downloads another malware detected as WORM_KILLAV.AI. This malware disables and terminates antivirus software processes, and drops other malware on the affected system.
As of this writing, all domains are blocked already by Smart Protection Network. Furthermore, OfficeScan users with Intrusion Defense Firewall plugin installed are protected from this threat if they have updated to the latest filters (IDF09021).



