Showing posts with label CVE-2009-0927. Show all posts
Showing posts with label CVE-2009-0927. Show all posts
Wednesday, January 19, 2011
Jan 12 CVE-2010-3654 + CVE-2009-4324 + CVE-2009-0927 + CVE-2008-0655 PDF JANUARY 2011 from a compromised Thai Police account
File JAN 2011.pdf
Posted by
Mila
at
12:13 AM
0
comments
Tags:
CVE-2008-0655,
CVE-2009-0927,
CVE-2009-4324,
CVE-2010-3654
Friday, November 26, 2010
CVE-2009-4324 CVE-2009-0927 CVE-2008-2992 regional security in east asia.pdf
Common Vulnerabilities and Exposures (CVE)number
This post is to be continued..
CVE-2009-4324
CVE-2009-0927
CVE-2008-2992
General File Information
File regional security in east asia.pdf
MD5 80e5432f7806564c5fc50738741abf7
SHA1 dc4f71609171e93bb1ad66fb52e8bb330f362a76
File size : 37238 bytes
Type: PDF
Distribution: Email attachment
Download
Thursday, September 9, 2010
Sep 09 CVE-2009-4324 + CVE-2010-1297 + CVE-2009-0927 PDF U.S. economy slips from spoofed henryAron@brookings.org 210.64.253.96
Download as a password protected archive with the original PDf and analysis files/dropped binaries (contact me if you need the password)
-----Original Message-----
From: Henry J. Aaron [mailto:henryAron@brookings.org]
Sent: Thursday, September 09, 2010 9:38 AM
To: XXXXXXXXX
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To whom it may concern.
Henry J. Aaron
Senior Fellow, Economic Studies
The Brookings Institution
Headers
Received: (qmail 12137 invoked from network); 9 Sep 2010 13:43:33 -0000
Received: from h96-210-64-253.seed.net.tw (HELO brookings.org) (210.64.253.96)
by XXXXXXXXXXXX with SMTP; 9 Sep 2010 13:43:33 -0000
From: "Henry J. Aaron"
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To: XXXXXXX
Content-Type: multipart/mixed;
boundary="=_NextPart_2rfkindysadvnqw3nerasdf"; charset="US-ASCII"
MIME-Version: 1.0
Reply-To: h.swain65@yahoo.com
Date: Thu, 9 Sep 2010 21:37:54 +0800
X-Priority: 3
X-Mailer: Microsoft Outlook Express 5.00.2615.200
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To: XXXXXXX
Content-Type: multipart/mixed;
boundary="=_NextPart_2rfkindysadvnqw3nerasdf"; charset="US-ASCII"
MIME-Version: 1.0
Reply-To: h.swain65@yahoo.com
Date: Thu, 9 Sep 2010 21:37:54 +0800
X-Priority: 3
X-Mailer: Microsoft Outlook Express 5.00.2615.200
210.64.253.96
ISP: Digital United Inc.
Organization: Seednet-TaipeiDP-S
State/Region: T'ai-pei
City: Taipei
CVE-2009-4324
CVE-2010-1297
CVE-2009-0927
http://wepawet.cs.ucsb.edu/view.php?hash=47a46ba2220cf6368eb0d42d8a6d40e3&type=js
Tuesday, August 3, 2010
Aug 3 CVE-2009-0927 + CVE-2009-4324 + CVE-2007-5659 Please confirm from 94255015@nccu.edu.tw 140.119.166.13
Download 350924123cbf1b126f4e38335ed6660d + files dropped as a password protected archive (contact me if you need the password)
-----Original Message-----
From: 94255015 [mailto:94255015@nccu.edu.tw]
Sent: Tuesday, August 03, 2010 11:24 AM
To: xxxxxxxxx
Subject: Please confirm~
Dear xxxxxxxxxxxxxxxx:
I'm very sorry to bother you,but please to make sure you have attended the meetings,and to confirm the agenda is correct.Thank you very much!
Your sincerely,
Aaron
Headers
Received: (qmail 6491 invoked from network); 3 Aug 2010 15:08:01 -0000
Received: from alumni2.nccu.edu.tw (HELO alumni2.nccu.edu.tw) (140.119.166.13)
by xxxxxxxxxxxx
Received: By OpenMail Mailer;Tue, 03 Aug 2010 23:24:24 +0800 (CST)
From: "94255015" <94255015@nccu.edu.tw>
Reply-To: 94255015@nccu.edu.tw
Subject: Please confirm~
Message-ID: <1280849064.24992.94255015@nccu.edu.tw>
To: "xxxxxxxxx
Date: Tue, 3 Aug 2010 23:24:24 +0800
MIME-Version: 1.0
Return-Path: 94255015@nccu.edu.tw
Content-Type: multipart/mixed; boundary="---=Z8PIZ9?YwlMVFpoZJ2WvJ=sMbD"
140.119.166.13
Hostname: alumni2.nccu.edu.tw
ISP: MOEC
Organization: National Chengchi University
Proxy: None detected
Type: Broadband
Country: Taiwan
File name:conference_program.pdf
http://www.virustotal.com/file-scan/report.html?id=220a1b24e02c2757eccebb6827b4021d570b0f662dd1b0772c22c96b8f6b7c1d-1282772703
Submission date:
2010-08-25 21:45:03 (UTC)
Current status:
17 /42 (40.5%)
Authentium 5.2.0.5 2010.08.25 PDF/Obfusc.G!Camelot
Avast 4.8.1351.0 2010.08.25 JS:Pdfka-gen
Avast5 5.0.594.0 2010.08.25 JS:Pdfka-gen
BitDefender 7.2 2010.08.25 Exploit.PDF-JS.Gen
ClamAV 0.96.2.0-git 2010.08.25 Heuristics.PDF.ObfuscatedNameObject
DrWeb 5.0.2.03300 2010.08.25 Exploit.PDF.1302
Emsisoft 5.0.0.37 2010.08.25 HTML.Malicious!IK
eSafe 7.0.17.0 2010.08.25 PDF.Exploit.4
F-Prot 4.6.1.107 2010.08.25 JS/ShellCode.S
F-Secure 9.0.15370.0 2010.08.25 Exploit.PDF-JS.Gen
GData 21 2010.08.25 Exploit.PDF-JS.Gen
Ikarus T3.1.1.88.0 2010.08.25 HTML.Malicious
Kaspersky 7.0.0.125 2010.08.25 Exploit.JS.Pdfka.cri
nProtect 2010-08-25.02 2010.08.25 Exploit.PDF-Name.Gen
VBA32 3.12.14.0 2010.08.25 Exploit.JS.Pdfka.cri
Additional information
Show all
MD5 : 350924123cbf1b126f4e38335ed6660d
CVE-2009-0927 + CVE-2009-4324 + CVE-2007-5659
____________________________________
CVE-2009-0927
for (i = 0; i < buffersize; i ++ ){
buffer[i] = unescape("%0a%0a%0a%0a");
}
var strtmp3 = "Collab.get" + "Icon(buffer+'_N.bundle');";
eval(strtmp3);
---------------------------------------------------------
CVE-2009-4324
for (i = 0; i < 200; i ++ )memory[i] = block + shellcode;
try {
this .media.newPlayer(null);
}
catch (e){
}
util.printd(String.fromCharCode(2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570,
2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570
, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570), new Date());
}
----------------------------------------------------------------------
CVE-2007-5659
if (app.viewerVersion >= 6.0){
this .collabStore = Collab.collectEmailInfo({
subj : "", msg : plin
Wepawet
http://wepawet.iseclab.org/view.php?hash=350924123cbf1b126f4e38335ed6660d&type=js
---------------------
Windows XP SP2 Adobe Reader 9.11
Created files
%userprofile%\Application Data\diskchk.exe 379E0B3E2C4778075511C4C1E62C0C65
%userprofile%\Local Settings\Temp\2.tmp
C:\a.pdf
%userprofile%\Local Settings\Temp\2.tmp
C:\a.pdf
a.pdf
File name:
diskchk.exe
diskchk.exe
http://www.virustotal.com/file-scan/report.html?id=5ab0bc8ef4f276e2b8a8fa989aa8e35947f1f1a2694f786ab02d4d4b7eeab2d6-1282823469
Submission date:
2010-08-26 11:51:09 (UTC)
Result:
10/ 40 (25.0%)
AntiVir 8.2.4.46 2010.08.26 TR/Crypt.ZPACK.Gen
Avast 4.8.1351.0 2010.08.26 Win32:Malware-gen
Avast5 5.0.594.0 2010.08.26 Win32:Malware-gen
AVG 9.0.0.851 2010.08.26 BackDoor.Generic12.BUOQ
BitDefender 7.2 2010.08.26 Gen:Trojan.Heur.RP.bu0@a86LzSfb
CAT-QuickHeal 11.00 2010.08.24 (Suspicious) - DNAScan
F-Secure 9.0.15370.0 2010.08.26 Gen:Trojan.Heur.RP.bu0@a86LzSfb
GData 21 2010.08.26 Gen:Trojan.Heur.RP.bu0@a86LzSfb
nProtect 2010-08-26.01 2010.08.26 Trojan/W32.Agent.28160.MA
Sophos 4.56.0 2010.08.26 Troj/FkIntel-A
Additional information
Show all
MD5 : 379e0b3e2c4778075511c4c1e62c0c65
Submission date:
2010-08-26 11:51:09 (UTC)
Result:
10/ 40 (25.0%)
AntiVir 8.2.4.46 2010.08.26 TR/Crypt.ZPACK.Gen
Avast 4.8.1351.0 2010.08.26 Win32:Malware-gen
Avast5 5.0.594.0 2010.08.26 Win32:Malware-gen
AVG 9.0.0.851 2010.08.26 BackDoor.Generic12.BUOQ
BitDefender 7.2 2010.08.26 Gen:Trojan.Heur.RP.bu0@a86LzSfb
CAT-QuickHeal 11.00 2010.08.24 (Suspicious) - DNAScan
F-Secure 9.0.15370.0 2010.08.26 Gen:Trojan.Heur.RP.bu0@a86LzSfb
GData 21 2010.08.26 Gen:Trojan.Heur.RP.bu0@a86LzSfb
nProtect 2010-08-26.01 2010.08.26 Trojan/W32.Agent.28160.MA
Sophos 4.56.0 2010.08.26 Troj/FkIntel-A
Additional information
Show all
MD5 : 379e0b3e2c4778075511c4c1e62c0c65
http://anubis.iseclab.org/?action=result&task_id=1f9a7a78ebc252b74a1362b81134726d7
DNS
audnted.flinkup.org 220.246.73.187
facecache.mypicture.info 220.246.73.187
microinfo.3utilities.com 255.255.255.255220.246.73.187
http://www.robtex.com/ip/220.246.73.187.html#whois
Hostname: 187.73.246.220.static.netvigator.com
ISP: PCCW Limited
Organization: PCCW Limited
Type: Broadband
Assignment: Dynamic IP
Country: Hong Kong
City: Kings Park
http://www.robtex.com/dns/187.73.246.220.static.netvigator.com.html#graph
Posted by
Mila
at
8:18 AM
0
comments
Tags:
**File-Analysis**,
CVE-2007-5659,
CVE-2009-0927,
CVE-2009-4324
Sunday, June 27, 2010
Jun 27 CVE-2009-0927 PDF Discussion on cross-strait maritime cooperation
CVE-2009-0927 Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before
9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to
execute arbitrary code via a crafted argument to the getIcon method of
a Collab object, a different vulnerability than CVE-2009-0658.
Download 6e14c7a424c2eef7f37810ff65650837 ATT27173.pdf as a password protected archive (contact me if you need the password)
http://www.virustotal.com/analisis/6ed5186f31852eb5533670ae0d08737940148fe8587bdc44c5474426d92362c7-1278222138
Result: 11/41 (26.83%)
Antivirus Version Last Update Result
Avast 4.8.1351.0 2010.07.03 JS:Pdfka-AIX
Avast5 5.0.332.0 2010.07.03 JS:Pdfka-AIX
BitDefender 7.2 2010.07.04 Exploit.PDF-JS.Gen
eSafe 7.0.17.0 2010.06.30 Win32.Pidief.D
F-Secure 9.0.15370.0 2010.07.03 Exploit.PDF-JS.Gen
GData 21 2010.07.04 Exploit.PDF-JS.Gen
Kaspersky 7.0.0.125 2010.07.04 Exploit.JS.Pdfka.cnj
McAfee-GW-Edition 2010.1 2010.07.02 Heuristic.BehavesLike.JS.BufferOverflow.D
nProtect 2010-07-04.01 2010.07.04 Exploit.PDF-JS.Gen
PCTools 7.0.3.5 2010.07.02 Trojan.Pidief
Symantec 20101.1.0.89 2010.07.04 Trojan.Pidief.D
Additional information
File size: 132181 bytes
MD5...: 6e14c7a424c2eef7f37810ff65650837
Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=6e14c7a424c2eef7f37810ff65650837&type=js
| Adobe getIcon | Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object | CVE-2009-0927 |
From: ³Å¼¢©t [mailto:guanpen@gio.gov.tw]
Sent: Sunday, June 27, 2010 9:23 PM
To: achengster@gmail.com
Subject: 兩岸海上合作芻議
釐清當前兩岸合作的理由、方式、目的、地點與自我檢討。
-----------------------------------------------------------------
中華孫子兵法研究學會
會長傅慰孤
Terrible machine translation :)
From: ³ Å ¼ ¢ © t
[mailto: guanpen@gio.gov.tw]
Sent: Sunday,June 27, 2010 9:23 PM
To: achengster@gmail.com
Subject: Discussion on cross-strait maritime cooperation
Clarify the reasons for the current cross-strait cooperation, methods, purpose, location and self-examination.
-------------------------------------------------- ---------------Research Institute of Chinese Art of WarFu Wei-ku, president of
[mailto: guanpen@gio.gov.tw]
Sent: Sunday,June 27, 2010 9:23 PM
To: achengster@gmail.com
Subject: Discussion on cross-strait maritime cooperation
Clarify the reasons for the current cross-strait cooperation, methods, purpose, location and self-examination.
-------------------------------------------------- ---------------Research Institute of Chinese Art of WarFu Wei-ku, president of
Posted by
Mila
at
1:51 AM
0
comments
Tags:
- ADOBE READER + ACROBAT 7.1.0,
- ADOBE READER + ACROBAT 8.1.3,
- ADOBE READER + ACROBAT 9.0,
CVE-2009-0927,
Samples
Friday, May 14, 2010
Phoenix 2.0 Exploit kit
I normally do not post exploit packs, even partial but I am posting it in this case as it appears to be the source of the java files analyzed by InReverse. Read
this for more details and Java analysis.
The other possibility is the Crimepack. Let me know if there are others, I may post them too.
Download Phoenix2.zip as a password protected archive (contact me if you need the password)List of included files
AdgredY.java 11895 416ff21ed3ddb4ce5665a4917964c5ce
all.js 5167 9432b83d52fc325f5bda83d58598e825 -- All listed except newplayer cve-2009-4324
deie.html 15097 a88f45102b57595d6c7b1cf2c2b4b241 --
flash.as 2746 718803346bbbed11e934c63af99c4a9f
ie.html 14939 1c8bd04644942a0f1832844ee4b44e63
newplayer.js 2595 a2344d3a54f26ae863011323a0973ac8 newplayer cve-2009-4324
| Filename | MD5 | File Size | Extension | |
|---|---|---|---|---|
| flash.swf | C643C2B8E901E52C14A8D6CE8096E327 | 1,645 | swf | |
| all.pdf | 66BDB0DC68294890E359E91F1EF18D9E | 2,677 | ||
| allv7.pdf | B948321DE93582951598F3BDDDCC5735 | 2,465 | ||
| collab.pdf | EF68F7B0018EDA2C149EF92EAAA666E2 | 2,012 | CVE-2007-5659 | |
| geticon.pdf | 1ED11F0EEE47135067F36E73FD5E889E | 2,003 | CVE-2009-0927 | |
| libtiff.pdf | E1E581CC0D817A808DC33CEB230F91B4 | 3,514 | CVE-2010-0188 | |
| newplayer.pdf | 37F28E5BE542AD2E32DA19EE5C44967C | 1,975 | CVE-2009-4324 | |
| printf.pdf | AF680ECCA07B3294553F672F78554588 | 1,907 | CVE-2008-2992 | |
| index.js | B07E39D831F8EA3F8BCD84DCC9A60FFF | 14,272 | js | |
| des.jar | 98F5ACDB21E8B8116FE5C7B4BA17D0E9 | 8,539 | jar | |
| ie.html | 30C1A7B87C419A1427932773642FEEE7 | 14,929 | CVE-2009-3867 | html |
| index.html | 9939596B9BA5ECD4EE5FD648171EF01C | 14,462 | html | |
| vistaie7.html | E8888E4EDA75F6CE016A5FBA9BE02FA3 | 14,415 | html | |
| vistan7ie8.html | 6D11908E6CCC01B14ED0097561853F86 | 8,747 | html | |
| vistan7other.html | 3E4B94ED2A6ED5F7FF42165BB165A46B | 13,734 | html | |
| xpie7.html | EDE58120D8C76212E458898B348D2B80 | 14,420 | html | |
| xpie8.html | A18CCEEE89E13B137C77F88688668CED | 8,714 | html | |
| xpother.html | 355A809F8B5BDE1E511C628DD75CD871 | 14,129 | html |
Flash exploits are
CVE-2009-1869
CVE-2007-0071
PDF exploits
CVE-2007-5659
CVE-2009-0927
CVE-2010-0188
CVE-2009-4324
CVE-2008-2992
Internet Explorer Exploits
CVE-2009-0806
Java Exploits
CVE-2009-3867
CVE-2008-5353
Let me know if i missed any
Java exploit GetSoundBank Read inReverse Ratsoul's posts for more information here or on their new blog here
Also, see some malware links with this exploit here
deie.html
MDAC exploit
Flashloader - using
object and embed for different browsers. Read this article for more details http://borodin.livejournal.com/10471.htmlActionscript
IE 2010-0806
Posted by
Mila
at
1:54 AM
4
comments
Tags:
- ADOBE READER + ACROBAT 7.1.0,
- ADOBE READER + ACROBAT 8.1.3,
- ADOBE READER + ACROBAT 8.1.7,
- ADOBE READER + ACROBAT 9.0,
- ADOBE READER + ACROBAT 9.2,
- INTERNET EXPLORER 6,
- JAVA,
CVE-2007-0071,
CVE-2007-5659,
CVE-2008-2992,
CVE-2008-5353,
CVE-2009-0806,
CVE-2009-0927,
CVE-2009-1869,
CVE-2009-3867,
CVE-2009-4324,
CVE-2010-0188,
Samples
Friday, April 2, 2010
Apr 2 CVE-2009-0927 CVE-2007-5659 PDF IPR in China FINAL from global.faruk@gmail.com
- CVE-2009-0927 Stack-based buffer overflow in Adobe via getIcon method of a Collab object, a different vulnerability than CVE-2009-0658 - March 2009.
- CVE-2007-5659 Multiple buffer overflows in Adobe via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
Download c497c02464ae74bbc94120d1cbe88d49 IPR in China FINAL.pdf as a password protected archive (contact me if you need the password)
Details c497c02464ae74bbc94120d1cbe88d49 IPR in China FINAL.pdf

From: Faruk DEMİR [mailto:global.faruk@gmail.com]
Sent: Friday, April 02, 2010 4:36 AM
To: XXXXXXXXXXXXXX
Subject: IPR in China FINAL
Virustotal
http://www.virustotal.com/analisis/816ff03f39d9d210ee3a49a61f208a4b0a8979c3d08fa9b8a17e01a98b5d123c-1270206094
File IPR_in_China_FINAL.pdf received on 2010.04.02 11:01:34 (UTC)
Result: 10/42 (23.81%)
a-squared 4.5.0.50 2010.04.02 Exploit.Win32.Pidief!IK
Authentium 5.2.0.5 2010.04.02 PDF/Obfusc.M!Camelot
Avast 4.8.1351.0 2010.04.02 JS:ShellCode-EQ
Avast5 5.0.332.0 2010.04.02 JS:ShellCode-EQ
AVG 9.0.0.787 2010.04.02 Exploit.PDF
GData 19 2010.04.02 JS:ShellCode-EQ
Ikarus T3.1.1.80.0 2010.04.02 Exploit.Win32.Pidief
Microsoft 1.5605 2010.04.02 Exploit:JS/Mult.CM
Symantec 20091.2.0.41 2010.04.02 Bloodhound.PDF!gen
TrendMicro 9.120.0.1004 2010.04.02 Expl_ShellCodeSM
File size: 54720 bytes
MD5 : c497c02464ae74bbc94120d1cbe88d49
Vicheck
https://www.vicheck.ca/md5query.php?hash=c497c02464ae74bbc94120d1cbe88d49
PDF Exploit call to Collab.collectEmailInfo CVE-2007-5659
PDF Exploit call to Collab.getIcon CVE-2009-0927
Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=c497c02464ae74bbc94120d1cbe88d49&type=js
suspicious
PDF Exploit call to Collab.collectEmailInfo CVE-2007-5659
PDF Exploit call to Collab.getIcon CVE-2009-0927
Wednesday, February 3, 2010
Feb 3 CVE-2009-0927 Former Minister of Finance Paulson's comments on Obama's $3.8 trillion budget from Simonbaker@aol.com
Download 2366453EE94A7BA4D296FA4E710ED805-CommentsOnObama2010budget as password protected archive (please contact me if you need the password)
Sent: Wednesday, February 03, 2010 10:04 PM
Subject: Former Minister of Finance Paulson's comments on Obama's $3.8 trillion budget
Hi,
If you have read Paulson's comments, you know how ridiculous Obama's $3.8 trillion budget is.
Please do not vote for members of support budget in November's elections.
Best regards
Virustotal
http://www.virustotal.com/analisis/783a6934a1c12c31f874f8246aa44c07d010480546bcb263fb3f090337a6874a-1266495353
File CommentsOnObama2010budget.pdf received on 2010.02.18 12:15:53 Result: 18/41 (43.91%)
a-squared 4.5.0.50 2010.02.18 Exploit.Win32.Pidief!IK
AhnLab-V3 5.0.0.2 2010.02.17 PDF/Exploit
AntiVir 8.2.1.170 2010.02.18 HTML/Silly.Gen
Antiy-AVL 2.0.3.7 2010.02.18 Exploit/Win32.Pidief
Authentium 5.2.0.5 2010.02.18 PDF/UtlPtf.B!Camelot
Avast 4.8.1351.0 2010.02.18 JS:Pdfka-ME
BitDefender 7.2 2010.02.18 Exploit.PDF-JS.Gen
ClamAV 0.96.0.0-git 2010.02.18 Exploit.PDF-11669
Comodo 3980 2010.02.18 TrojWare.Win32.Exploit.Pidief.bxf
| Kaspersky | 7.0.0.125 | Exploit.Win32.Pidief.bxf |
eSafe 7.0.17.0 2010.02.17 PDF.Exploit
F-Secure 9.0.15370.0 2010.02.18 Exploit.PDF-JS.Gen
GData 19 2010.02.18 Exploit.PDF-JS.Gen
Ikarus T3.1.1.80.0 2010.02.18 Exploit.Win32.Pidief
McAfee-GW-Edition 6.8.5 2010.02.18 Script.Silly.Gen
Sophos 4.50.0 2010.02.18 Troj/PDFJS-BX
Sunbelt 5684 2010.02.18 Exploit.PDF.Pidief (v)
VirusBuster 5.0.27.0 2010.02.18 JS.BOFExploit.Gen
Additional information
File size: 119239 bytes
MD5...: 2366453ee94a7ba4d296fa4e710ed805
Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=2366453ee94a7ba4d296fa4e710ed805&type=js
File CommentsOnObama2010budget.pdf
MD5 2366453ee94a7ba4d296fa4e710ed805
Analysis Started 2010-02-18 04:18:06
Report Generated 2010-02-18 04:21:39
Jsand 1.02.02 malicious
Adobe getIcon Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object CVE-2009-0927
Monday, January 11, 2010
Jan 11 CVE-2009-0927 CVE-2008-2992 China and Human Rights from jnfrlews@yahoo.com 2010.01.12 06:24:41 (UTC)
Details: AAF477AF8CFB73C6BD9945C5BE403FE9 - ChinaHR.pdf
From: Jennifer Lewis [mailto:jnfrlews@yahoo.com]
Sent: Monday, January 11, 2010 10:32 PM
To: XXXXXXXXXXXX
Subject: China and Human Rights
China's lack of political freedoms
Opinion towards China brings mixed agendas
China's poor attempt to deflect attention
Resentment of Chinese economic policy not benefiting locals
Lack of international unity, despite statements by media and world leaders
China's actions fuels the very thing it says it tries to fight
China and Africa; concerns over rights and exploitation
More information...
File ChinaHR.pdf received on 2010.01.12 06:24:41 (UTC)
The message sender was
jnfrlews@yahoo.com
The message originating IP was 68.142.206.41 The message recipients were
XXXXXXXXXXXXX
The message was titled China and Human Rights The message date was Mon, 11 Jan 2010 19:31:56 -0800 (PST) The message identifier was <54825.40062.qm@web113916.mail.gq1.yahoo.com>
attach/5963841_3X_PM5_EMS_MA-PDF__ChinaHR.pdf: Infected: Exploit.Win32.Pidief.bxf [AVP]
The message sender was
jnfrlews@yahoo.com
The message originating IP was 68.142.206.41 The message recipients were
XXXXXXXXXXXXX
The message was titled China and Human Rights The message date was Mon, 11 Jan 2010 19:31:56 -0800 (PST) The message identifier was <54825.40062.qm@web113916.mail.gq1.yahoo.com>
attach/5963841_3X_PM5_EMS_MA-PDF__ChinaHR.pdf: Infected: Exploit.Win32.Pidief.bxf [AVP]
Virustotal
http://www.virustotal.com/analisis/b0c7da5ae8e22caeed88008c7847927a19fec7dd659746f6a124b08e3f95547b-1263277481
Result: 13/40 (32.5%)
AntiVir 7.9.1.134 2010.01.11 HTML/Silly.Gen
Antiy-AVL 2.0.3.7 2010.01.11 Exploit/Win32.Pidief
Authentium 5.2.0.5 2010.01.12 PDF/UtlPtf.B!Camelot
Avast 4.8.1351.0 2010.01.11 JS:Pdfka-ME
BitDefender 7.2 2010.01.12 Exploit.PDF-JS.Gen
eSafe 7.0.17.0 2010.01.11 PDF.Exploit
F-Secure 9.0.15370.0 2010.01.12 Exploit.PDF-JS.Gen
GData 19 2010.01.12 Exploit.PDF-JS.Gen
Kaspersky 7.0.0.125 2010.01.12 Exploit.Win32.Pidief.bxf
McAfee-GW-Edition 6.8.5 2010.01.12 Script.Silly.Gen
Sophos 4.49.0 2010.01.12 Troj/PDFJS-BX
Sunbelt 3.2.1858.2 2010.01.12 Exploit.PDF.Pidief (v)
VirusBuster 5.0.21.0 2010.01.11 JS.BOFExploit.Gen
Additional information
File size: 119239 bytes
MD5...: aaf477af8cfb73c6bd9945c5be403fe9
Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=aaf477af8cfb73c6bd9945c5be403fe9&type=js
| Adobe getIcon | Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object | CVE-2009-0927 |
Update January 18, 2010
jsunpack
Even better results were produced and submitted by Blake (thank you, Blake) using his jsunpack tool - see http://jsunpack.blogspot.com. Utilprintf CVE-2008-2992 was detected in addition to CollabgetIcon CVE-2009-0927.
jsunpack-n$ ./jsunpack-n.py ChinaHR.pdf -V
check line 1371
Processing ChinaHR.pdf
[malicious:10] [PDF] ChinaHR.pdf
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 6269 bytes (./files/decoding_
257729096ea832ff72e7365e34062d 183d69f2fe)
malicious: Utilprintf CVE-2008-2992 detected
malicious: CollabgetIcon CVE-2009-0927 detected
info: [decodingLevel=1] found JavaScript
info: saved original parsed JavaScript to ./files/veryverbose_257729096ea832ff72e7365e34062d 183d69f2fe
info: Decoding option app.viewerVersion=8.0, 4012 bytes
info: Decoding option app.viewerVersion= and app.viewerVersion=9.1, 0 bytes
info: [decodingLevel=1] decoded 4012 bytes (./files/decoding_93aa0a7dc84a9b7ef6fe87912af548 1a0d6a9f4d)
suspicious: Warning detected //warning CVE-NO-MATCH Shellcode NOP len 9999 //warning CVE-NO-MATCH Shellcode NOP len 506 //warning CVE-NO-MATCH Shellcode NOP len 297 //warning CVE-NO-MATCH Shellcode NOP len 261833
malicious: shellcode of length 565/295 (./files/shellcode_2b5537e1a69fa16a8c625e0087023c 9506002d7e)
malicious: shellcode of length 551/277 (./files/shellcode_e9f9df40fb0abdc9c6b119423800ca 9d0583411c)
info: [2] no JavaScript
info: [file] saved ChinaHR.pdf to (./files/original_074517645ec0b7e50bc788910dda51 c0e9dcd889)
[file] created ./files/decoding_257729096ea832ff72e7365e34062d 183d69f2fe from ChinaHR.pdf
[file] created ./files/veryverbose_257729096ea832ff72e7365e34062d 183d69f2fe from ChinaHR.pdf
[file] created ./files/decoding_93aa0a7dc84a9b7ef6fe87912af548 1a0d6a9f4d from ChinaHR.pdf
[file] created ./files/shellcode_2b5537e1a69fa16a8c625e0087023c 9506002d7e from ChinaHR.pdf
[file] created ./files/shellcode_e9f9df40fb0abdc9c6b119423800ca 9d0583411c from ChinaHR.pdf
[file] created ./files/original_074517645ec0b7e50bc788910dda51 c0e9dcd889 from ChinaHR.pdf
Friday, November 6, 2009
Nov.6 PDF attack. Obama visit Asia from [username]098@gmail.com Nov 6, 2009 8:38:57 AM
- CVE-2009-0927 Stack-based buffer overflow in Adobe via getIcon method of a Collab object, a different vulnerability than CVE-2009-0658 - March 2009.
- CVE-2007-5659 Multiple buffer overflows in Adobe via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
Possible MalWare 'Exploit/Zordle.gen' found in '5963792_3X_PM5_EMS_MA-PDF__Obama=20visit=20Asia.pdf'. Heuristics score: 201
From: "[REMOVED]" [mailto:098@gmail.com
Sent: Friday, November 6, 2009 8:38:57 AM GMT -05:00 US/Canada Eastern
Subject: Obama's visit to Asia
Dear Colleagues,
With the upcoming Obama's visit to Asia, please find the attached paper for your kind reference.
Should you have any questions, please contact me.
Best regards,
--
signature here [REMOVED]
File Obama_visit_Asia.pdf received on 2009.11.06 18:05:36 (UTC)
Current status: finished
Result: 4/41 (9.76%)
| Antivirus | Version | Last Update | Result |
|---|---|---|---|
| a-squared | 4.5.0.41 | 2009.11.06 | - |
| AhnLab-V3 | 5.0.0.2 | 2009.11.06 | - |
| AntiVir | 7.9.1.59 | 2009.11.06 | - |
| Antiy-AVL | 2.0.3.7 | 2009.11.05 | - |
| Authentium | 5.2.0.5 | 2009.11.06 | PDF/Pidief.O |
| Avast | 4.8.1351.0 | 2009.11.06 | - |
| AVG | 8.5.0.423 | 2009.11.06 | - |
| BitDefender | 7.2 | 2009.11.06 | Exploit.PDF-JS.Gen |
| CAT-QuickHeal | 10.00 | 2009.11.06 | - |
| ClamAV | 0.94.1 | 2009.11.06 | - |
| Comodo | 2862 | 2009.11.06 | - |
| DrWeb | 5.0.0.12182 | 2009.11.06 | - |
| eSafe | 7.0.17.0 | 2009.11.05 | - |
| eTrust-Vet | 35.1.7107 | 2009.11.06 | - |
| F-Prot | 4.5.1.85 | 2009.11.06 | - |
| F-Secure | 9.0.15370.0 | 2009.11.04 | Exploit.PDF-JS.Gen |
| Fortinet | 3.120.0.0 | 2009.11.06 | - |
| GData | 19 | 2009.11.06 | Exploit.PDF-JS.Gen |
| Ikarus | T3.1.1.74.0 | 2009.11.06 | - |
| Jiangmin | 11.0.800 | 2009.11.06 | - |
| K7AntiVirus | 7.10.890 | 2009.11.06 | - |
| Kaspersky | 7.0.0.125 | 2009.11.06 | - |
| McAfee | 5793 | 2009.11.05 | - |
| McAfee+Artemis | 5794 | 2009.11.06 | - |
| McAfee-GW-Edition | 6.8.5 | 2009.11.06 | - |
| Microsoft | 1.5202 | 2009.11.06 | - |
| NOD32 | 4580 | 2009.11.06 | - |
| Norman | 6.03.02 | 2009.11.06 | - |
| nProtect | 2009.1.8.0 | 2009.11.06 | - |
| Panda | 10.0.2.2 | 2009.11.05 | - |
| PCTools | 7.0.3.5 | 2009.11.06 | - |
| Prevx | 3.0 | 2009.11.06 | - |
| Rising | 21.54.44.00 | 2009.11.06 | - |
| Sophos | 4.47.0 | 2009.11.06 | - |
| Sunbelt | 3.2.1858.2 | 2009.11.06 | - |
| Symantec | 1.4.4.12 | 2009.11.06 | - |
| TheHacker | 6.5.0.2.062 | 2009.11.05 | - |
| TrendMicro | 9.0.0.1003 | 2009.11.06 | - |
| VBA32 | 3.12.10.11 | 2009.11.06 | - |
| ViRobot | 2009.11.6.2025 | 2009.11.06 | - |
| VirusBuster | 4.6.5.0 | 2009.11.06 | - |
File | Obama visit Asia.pdf |
|---|---|
| MD5 | 33aa28b079b33c1609f9096ee78e73c8 |
| Analysis Started | 2009-11-06 12:10:45 |
| Report Generated | 2009-11-06 12:10:53 |
| Jsand version | 1.03.02 |
Detection results
| Detector | Result |
|---|---|
| Jsand 1.03.02 | malicious |
Exploits
| Name | Description | Reference |
|---|---|---|
| Adobe Collab overflow | Multiple Adobe Reader and Acrobat buffer overflows | CVE-2007-5659 |
| Adobe getIcon | Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object | CVE-2009-0927 |
Subscribe to:
Posts (Atom)









