Clicky

Pages

Showing posts with label CVE-2009-0927. Show all posts
Showing posts with label CVE-2009-0927. Show all posts

Wednesday, January 19, 2011

Jan 12 CVE-2010-3654 + CVE-2009-4324 + CVE-2009-0927 + CVE-2008-0655 PDF JANUARY 2011 from a compromised Thai Police account

Common Vulnerabilities and Exposures (CVE)number

CVE-2010-3654 Adobe Flash Player 10.1.85.3 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.95.2 and earlier on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.

 

CVE-2009-4324 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.  

 

CVE-2009-0927 Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.  

 

CVE-2008-0655 Buffer overflow via specially crafted arguments to Collab.collectEmailInfo

  General File Information

File  JAN 2011.pdf
MD5  F928C39F0BFEBAAF3A5FB149557DDF66
SHA1
  87c17dc9282792906ef41670011c2473c87c9b9b   
File size :  384271
Type:  PDF
Distribution: Email attachment
 

read more...

Friday, November 26, 2010

CVE-2009-4324 CVE-2009-0927 CVE-2008-2992 regional security in east asia.pdf


Common Vulnerabilities and Exposures (CVE)number

This post is to be continued..

CVE-2009-4324

CVE-2009-0927

CVE-2008-2992

  General File Information

File regional security in east asia.pdf
MD5  80e5432f7806564c5fc50738741abf7
SHA1  dc4f71609171e93bb1ad66fb52e8bb330f362a76
File size 37238 bytes
Type:  PDF
Distribution: Email attachment

Download

Thursday, September 9, 2010

Sep 09 CVE-2009-4324 + CVE-2010-1297 + CVE-2009-0927 PDF U.S. economy slips from spoofed henryAron@brookings.org 210.64.253.96



CVE-2009-0927 Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.


Download  as a password protected archive with the original PDf and analysis files/dropped binaries (contact me if you need the password)


-----Original Message-----
From: Henry J. Aaron [mailto:henryAron@brookings.org]
Sent: Thursday, September 09, 2010 9:38 AM
To: XXXXXXXXX
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings

To whom it may concern.

Henry J. Aaron

Senior Fellow, Economic Studies

The Brookings Institution
Headers
Received: (qmail 12137 invoked from network); 9 Sep 2010 13:43:33 -0000
Received: from h96-210-64-253.seed.net.tw (HELO brookings.org) (210.64.253.96)
  by XXXXXXXXXXXX with SMTP; 9 Sep 2010 13:43:33 -0000
From: "Henry J. Aaron"
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To: XXXXXXX
Content-Type: multipart/mixed;
    boundary="=_NextPart_2rfkindysadvnqw3nerasdf"; charset="US-ASCII"
MIME-Version: 1.0
Reply-To: h.swain65@yahoo.com
Date: Thu, 9 Sep 2010 21:37:54 +0800
X-Priority: 3
X-Mailer: Microsoft Outlook Express 5.00.2615.200

210.64.253.96

Hostname:    h96-210-64-253.seed.net.tw
ISP:    Digital United Inc.
Organization:    Seednet-TaipeiDP-S
State/Region:    T'ai-pei
City:    Taipei

CVE-2009-4324
CVE-2010-1297
CVE-2009-0927
http://wepawet.cs.ucsb.edu/view.php?hash=47a46ba2220cf6368eb0d42d8a6d40e3&type=js


Tuesday, August 3, 2010

Aug 3 CVE-2009-0927 + CVE-2009-4324 + CVE-2007-5659 Please confirm from 94255015@nccu.edu.tw 140.119.166.13



Download 350924123cbf1b126f4e38335ed6660d + files dropped as a password protected archive (contact me if you need the password)





-----Original Message-----
From: 94255015 [mailto:94255015@nccu.edu.tw]
Sent: Tuesday, August 03, 2010 11:24 AM
To: xxxxxxxxx
Subject: Please confirm~


Dear xxxxxxxxxxxxxxxx:

I'm very sorry to bother you,but please to make sure you have attended the meetings,and to confirm the agenda is correct.Thank you very much!

Your sincerely,
Aaron

 Headers
Received: (qmail 6491 invoked from network); 3 Aug 2010 15:08:01 -0000
Received: from alumni2.nccu.edu.tw (HELO alumni2.nccu.edu.tw) (140.119.166.13)
  by xxxxxxxxxxxx
Received: By OpenMail Mailer;Tue, 03 Aug 2010 23:24:24 +0800 (CST)
From: "94255015" <94255015@nccu.edu.tw>
Reply-To: 94255015@nccu.edu.tw
Subject: Please confirm~
Message-ID: <1280849064.24992.94255015@nccu.edu.tw>
To: "xxxxxxxxx
Date: Tue, 3 Aug 2010 23:24:24 +0800
MIME-Version: 1.0
Return-Path: 94255015@nccu.edu.tw
Content-Type: multipart/mixed; boundary="---=Z8PIZ9?YwlMVFpoZJ2WvJ=sMbD"
 
140.119.166.13
 Hostname:    alumni2.nccu.edu.tw
ISP:    MOEC
Organization:    National Chengchi University
Proxy:    None detected
Type:    Broadband
Country:    Taiwan


File name:conference_program.pdf
http://www.virustotal.com/file-scan/report.html?id=220a1b24e02c2757eccebb6827b4021d570b0f662dd1b0772c22c96b8f6b7c1d-1282772703
Submission date:
2010-08-25 21:45:03 (UTC)
Current status:
17 /42 (40.5%)
Authentium     5.2.0.5     2010.08.25     PDF/Obfusc.G!Camelot
Avast     4.8.1351.0     2010.08.25     JS:Pdfka-gen
Avast5     5.0.594.0     2010.08.25     JS:Pdfka-gen
BitDefender     7.2     2010.08.25     Exploit.PDF-JS.Gen
ClamAV     0.96.2.0-git     2010.08.25     Heuristics.PDF.ObfuscatedNameObject
DrWeb     5.0.2.03300     2010.08.25     Exploit.PDF.1302
Emsisoft     5.0.0.37     2010.08.25     HTML.Malicious!IK
eSafe     7.0.17.0     2010.08.25     PDF.Exploit.4
F-Prot     4.6.1.107     2010.08.25     JS/ShellCode.S
F-Secure     9.0.15370.0     2010.08.25     Exploit.PDF-JS.Gen
GData     21     2010.08.25     Exploit.PDF-JS.Gen
Ikarus     T3.1.1.88.0     2010.08.25     HTML.Malicious
Kaspersky     7.0.0.125     2010.08.25     Exploit.JS.Pdfka.cri
nProtect     2010-08-25.02     2010.08.25     Exploit.PDF-Name.Gen
VBA32     3.12.14.0     2010.08.25     Exploit.JS.Pdfka.cri
Additional information
Show all
MD5   : 350924123cbf1b126f4e38335ed6660d


CVE-2009-0927 + CVE-2009-4324 + CVE-2007-5659

____________________________________
CVE-2009-0927

for (i = 0; i < buffersize; i ++ ){
buffer[i] = unescape("%0a%0a%0a%0a");
}
var strtmp3 = "Collab.get" + "Icon(buffer+'_N.bundle');";
eval(strtmp3);
---------------------------------------------------------
CVE-2009-4324

for (i = 0; i < 200; i ++ )memory[i] = block + shellcode;
try {
this .media.newPlayer(null);
}
catch (e){
}
util.printd(String.fromCharCode(2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570,
2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570
, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570), new Date());
}
----------------------------------------------------------------------
CVE-2007-5659

if (app.viewerVersion >= 6.0){
this .collabStore = Collab.collectEmailInfo({
subj : "", msg : plin

Wepawet
http://wepawet.iseclab.org/view.php?hash=350924123cbf1b126f4e38335ed6660d&type=js 

 ---------------------

Windows XP SP2 Adobe Reader 9.11

Created files
%userprofile%\Application Data\diskchk.exe  379E0B3E2C4778075511C4C1E62C0C65
%userprofile%\Local Settings\Temp\2.tmp 
C:\a.pdf 

a.pdf

File name:
diskchk.exe
http://www.virustotal.com/file-scan/report.html?id=5ab0bc8ef4f276e2b8a8fa989aa8e35947f1f1a2694f786ab02d4d4b7eeab2d6-1282823469
Submission date:
2010-08-26 11:51:09 (UTC)
Result:
10/ 40 (25.0%)
AntiVir    8.2.4.46    2010.08.26    TR/Crypt.ZPACK.Gen
Avast    4.8.1351.0    2010.08.26    Win32:Malware-gen
Avast5    5.0.594.0    2010.08.26    Win32:Malware-gen
AVG    9.0.0.851    2010.08.26    BackDoor.Generic12.BUOQ
BitDefender    7.2    2010.08.26    Gen:Trojan.Heur.RP.bu0@a86LzSfb
CAT-QuickHeal    11.00    2010.08.24    (Suspicious) - DNAScan
F-Secure    9.0.15370.0    2010.08.26    Gen:Trojan.Heur.RP.bu0@a86LzSfb
GData    21    2010.08.26    Gen:Trojan.Heur.RP.bu0@a86LzSfb
nProtect    2010-08-26.01    2010.08.26    Trojan/W32.Agent.28160.MA
Sophos    4.56.0    2010.08.26    Troj/FkIntel-A
Additional information
Show all
MD5   : 379e0b3e2c4778075511c4c1e62c0c65


Anubis report
http://anubis.iseclab.org/?action=result&task_id=1f9a7a78ebc252b74a1362b81134726d7




DNS 
audnted.flinkup.org 220.246.73.187
facecache.mypicture.info 220.246.73.187
microinfo.3utilities.com 255.255.255.255

220.246.73.187
http://www.robtex.com/ip/220.246.73.187.html#whois
Hostname:    187.73.246.220.static.netvigator.com
ISP:    PCCW Limited
Organization:    PCCW Limited
Type:    Broadband
Assignment:    Dynamic IP
Country:    Hong Kong
City:    Kings Park
http://www.robtex.com/dns/187.73.246.220.static.netvigator.com.html#graph



Sunday, June 27, 2010

Jun 27 CVE-2009-0927 PDF Discussion on cross-strait maritime cooperation

CVE-2009-0927 Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658. 

Download  6e14c7a424c2eef7f37810ff65650837 ATT27173.pdf as a password protected archive (contact me if you need the password)



 File ATT27173.pdf received on 2010.07.04 05:42:18 (UTC)
http://www.virustotal.com/analisis/6ed5186f31852eb5533670ae0d08737940148fe8587bdc44c5474426d92362c7-1278222138
Result: 11/41 (26.83%)
Antivirus     Version     Last Update     Result
Avast    4.8.1351.0    2010.07.03    JS:Pdfka-AIX
Avast5    5.0.332.0    2010.07.03    JS:Pdfka-AIX
BitDefender    7.2    2010.07.04    Exploit.PDF-JS.Gen
eSafe    7.0.17.0    2010.06.30    Win32.Pidief.D
F-Secure    9.0.15370.0    2010.07.03    Exploit.PDF-JS.Gen
GData    21    2010.07.04    Exploit.PDF-JS.Gen
Kaspersky    7.0.0.125    2010.07.04    Exploit.JS.Pdfka.cnj
McAfee-GW-Edition    2010.1    2010.07.02    Heuristic.BehavesLike.JS.BufferOverflow.D
nProtect    2010-07-04.01    2010.07.04    Exploit.PDF-JS.Gen
PCTools    7.0.3.5    2010.07.02    Trojan.Pidief
Symantec    20101.1.0.89    2010.07.04    Trojan.Pidief.D
Additional information
File size: 132181 bytes
MD5...: 6e14c7a424c2eef7f37810ff65650837


Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=6e14c7a424c2eef7f37810ff65650837&type=js

Adobe getIconStack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab objectCVE-2009-0927

From: ³Å¼¢©t [mailto:guanpen@gio.gov.tw]
Sent: Sunday, June 27, 2010 9:23 PM
To: achengster@gmail.com
Subject: 兩岸海上合作芻議

釐清當前兩岸合作的理由、方式、目的、地點與自我檢討。
 -----------------------------------------------------------------
中華孫子兵法研究學會
會長傅慰孤

Terrible machine translation :)
From: ³ Å ¼ ¢ © t
[mailto: guanpen@gio.gov.tw]
 Sent: Sunday,June 27, 2010 9:23 PM 
To: achengster@gmail.com 
Subject: Discussion on cross-strait maritime cooperation

Clarify the reasons for the current cross-strait cooperation, methods, purpose, location and self-examination.
 
-------------------------------------------------- ---------------Research Institute of Chinese Art of WarFu Wei-ku, president of


Friday, May 14, 2010

Phoenix 2.0 Exploit kit

I normally do not post exploit packs, even partial but I am posting it in this case as it appears to be the source of the java files analyzed by InReverse.  Read this for more details and Java analysis.
The other possibility is the Crimepack. Let me know if there are others, I may post them too.


 Download  Phoenix2.zip as a password protected archive (contact me if you need the password)

   

List of included files


AdgredY.java    11895    416ff21ed3ddb4ce5665a4917964c5ce
all.js    5167    9432b83d52fc325f5bda83d58598e825  -- All listed except newplayer cve-2009-4324
deie.html    15097    a88f45102b57595d6c7b1cf2c2b4b241  --
flash.as    2746    718803346bbbed11e934c63af99c4a9f
ie.html    14939    1c8bd04644942a0f1832844ee4b44e63
newplayer.js    2595    a2344d3a54f26ae863011323a0973ac8
newplayer cve-2009-4324


Filename MD5 File Size   Extension
flash.swfC643C2B8E901E52C14A8D6CE8096E3271,645swf
all.pdf66BDB0DC68294890E359E91F1EF18D9E2,677
pdf
allv7.pdfB948321DE93582951598F3BDDDCC57352,465pdf
collab.pdfEF68F7B0018EDA2C149EF92EAAA666E22,012 CVE-2007-5659 pdf
geticon.pdf1ED11F0EEE47135067F36E73FD5E889E2,003 CVE-2009-0927pdf
libtiff.pdfE1E581CC0D817A808DC33CEB230F91B43,514 CVE-2010-0188pdf
newplayer.pdf37F28E5BE542AD2E32DA19EE5C44967C1,975 CVE-2009-4324pdf
printf.pdfAF680ECCA07B3294553F672F785545881,907 CVE-2008-2992pdf
index.jsB07E39D831F8EA3F8BCD84DCC9A60FFF14,272js
des.jar98F5ACDB21E8B8116FE5C7B4BA17D0E98,539jar
ie.html30C1A7B87C419A1427932773642FEEE714,929 CVE-2009-3867 html
index.html9939596B9BA5ECD4EE5FD648171EF01C14,462html
vistaie7.htmlE8888E4EDA75F6CE016A5FBA9BE02FA314,415html
vistan7ie8.html6D11908E6CCC01B14ED0097561853F868,747html
vistan7other.html3E4B94ED2A6ED5F7FF42165BB165A46B13,734html
xpie7.htmlEDE58120D8C76212E458898B348D2B8014,420html
xpie8.htmlA18CCEEE89E13B137C77F88688668CED8,714html
xpother.html355A809F8B5BDE1E511C628DD75CD87114,129html

Flash exploits are

CVE-2009-1869
CVE-2007-0071

PDF exploits
 CVE-2007-5659
 CVE-2009-0927
 CVE-2010-0188
 CVE-2009-4324
 CVE-2008-2992

Internet Explorer Exploits
CVE-2009-0806

Java Exploits
CVE-2009-3867
CVE-2008-5353

Let me know if i missed any

Java exploit GetSoundBank Read inReverse Ratsoul's posts for more information here or on their new blog here 
Also, see some malware links with this exploit here





deie.html
MDAC exploit

 Flashloader - using object and embed for different browsers. Read this article for more details http://borodin.livejournal.com/10471.html


Actionscript

IE 2010-0806




Friday, April 2, 2010

Apr 2 CVE-2009-0927 CVE-2007-5659 PDF IPR in China FINAL from global.faruk@gmail.com


Download c497c02464ae74bbc94120d1cbe88d49 IPR in China FINAL.pdf as a password protected archive (contact me if you need the password)

Details c497c02464ae74bbc94120d1cbe88d49 IPR in China FINAL.pdf



From: Faruk DEMİR [mailto:global.faruk@gmail.com]
Sent: Friday, April 02, 2010 4:36 AM
To: XXXXXXXXXXXXXX
Subject: IPR in China FINAL










Virustotal
http://www.virustotal.com/analisis/816ff03f39d9d210ee3a49a61f208a4b0a8979c3d08fa9b8a17e01a98b5d123c-1270206094
File IPR_in_China_FINAL.pdf received on 2010.04.02 11:01:34 (UTC)
Result: 10/42 (23.81%)
a-squared     4.5.0.50     2010.04.02     Exploit.Win32.Pidief!IK
Authentium     5.2.0.5     2010.04.02     PDF/Obfusc.M!Camelot
Avast     4.8.1351.0     2010.04.02     JS:ShellCode-EQ
Avast5     5.0.332.0     2010.04.02     JS:ShellCode-EQ
AVG     9.0.0.787     2010.04.02     Exploit.PDF
GData     19     2010.04.02     JS:ShellCode-EQ
Ikarus     T3.1.1.80.0     2010.04.02     Exploit.Win32.Pidief
Microsoft     1.5605     2010.04.02     Exploit:JS/Mult.CM
Symantec     20091.2.0.41     2010.04.02     Bloodhound.PDF!gen
TrendMicro     9.120.0.1004     2010.04.02     Expl_ShellCodeSM
File size: 54720 bytes
MD5   : c497c02464ae74bbc94120d1cbe88d49

Vicheck
https://www.vicheck.ca/md5query.php?hash=c497c02464ae74bbc94120d1cbe88d49
PDF Exploit call to Collab.collectEmailInfo CVE-2007-5659
PDF Exploit call to Collab.getIcon CVE-2009-0927

Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=c497c02464ae74bbc94120d1cbe88d49&type=js
suspicious



PDF Exploit call to Collab.collectEmailInfo CVE-2007-5659
PDF Exploit call to Collab.getIcon CVE-2009-0927





























Wednesday, February 3, 2010

Feb 3 CVE-2009-0927 Former Minister of Finance Paulson's comments on Obama's $3.8 trillion budget from Simonbaker@aol.com

Download 2366453EE94A7BA4D296FA4E710ED805-CommentsOnObama2010budget as password protected archive (please contact me if you need the password)

From: Simon Baker [mailto:Simonbaker@aol.com]
Sent: Wednesday, February 03, 2010 10:04 PM
Subject: Former Minister of Finance Paulson's comments on Obama's $3.8 trillion budget

Hi,

If you have read Paulson's comments, you know how ridiculous Obama's $3.8 trillion budget is.
Please do not vote for members of support budget in November's elections.

Best regards

Virustotal
http://www.virustotal.com/analisis/783a6934a1c12c31f874f8246aa44c07d010480546bcb263fb3f090337a6874a-1266495353
 File CommentsOnObama2010budget.pdf received on 2010.02.18 12:15:53 Result: 18/41 (43.91%)
a-squared    4.5.0.50    2010.02.18    Exploit.Win32.Pidief!IK
AhnLab-V3    5.0.0.2    2010.02.17    PDF/Exploit
AntiVir    8.2.1.170    2010.02.18    HTML/Silly.Gen
Antiy-AVL    2.0.3.7    2010.02.18    Exploit/Win32.Pidief
Authentium    5.2.0.5    2010.02.18    PDF/UtlPtf.B!Camelot
Avast    4.8.1351.0    2010.02.18    JS:Pdfka-ME
BitDefender    7.2    2010.02.18    Exploit.PDF-JS.Gen
ClamAV    0.96.0.0-git    2010.02.18    Exploit.PDF-11669
Comodo    3980    2010.02.18    TrojWare.Win32.Exploit.Pidief.bxf
Kaspersky 7.0.0.125 Exploit.Win32.Pidief.bxf

eSafe    7.0.17.0    2010.02.17    PDF.Exploit
F-Secure    9.0.15370.0    2010.02.18    Exploit.PDF-JS.Gen
GData    19    2010.02.18    Exploit.PDF-JS.Gen
Ikarus    T3.1.1.80.0    2010.02.18    Exploit.Win32.Pidief
McAfee-GW-Edition    6.8.5    2010.02.18    Script.Silly.Gen
Sophos    4.50.0    2010.02.18    Troj/PDFJS-BX
Sunbelt    5684    2010.02.18    Exploit.PDF.Pidief (v)
VirusBuster    5.0.27.0    2010.02.18    JS.BOFExploit.Gen
Additional information
File size: 119239 bytes
MD5...: 2366453ee94a7ba4d296fa4e710ed805



Wepawet
 http://wepawet.cs.ucsb.edu/view.php?hash=2366453ee94a7ba4d296fa4e710ed805&type=js
 File    CommentsOnObama2010budget.pdf
MD5    2366453ee94a7ba4d296fa4e710ed805
Analysis Started    2010-02-18 04:18:06
Report Generated    2010-02-18 04:21:39
Jsand 1.02.02    malicious
Adobe getIcon    Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object    CVE-2009-0927




Monday, January 11, 2010

Jan 11 CVE-2009-0927 CVE-2008-2992 China and Human Rights from jnfrlews@yahoo.com 2010.01.12 06:24:41 (UTC)




Download ChinaHR.pdf as AAF477AF8CFB73C6BD9945C5BE403FE9-ChinaHR.zip (password protected, please contact me for the password)

Details: AAF477AF8CFB73C6BD9945C5BE403FE9 - ChinaHR.pdf



From: Jennifer Lewis [mailto:jnfrlews@yahoo.com]
Sent: Monday, January 11, 2010 10:32 PM
To: XXXXXXXXXXXX
Subject: China and Human Rights

China's lack of political freedoms
Opinion towards China brings mixed agendas
China's poor attempt to deflect attention
Resentment of Chinese economic policy not benefiting locals
Lack of international unity, despite statements by media and world leaders
China's actions fuels the very thing it says it tries to fight
China and Africa; concerns over rights and exploitation
More information...
File ChinaHR.pdf received on 2010.01.12 06:24:41 (UTC)
The message sender was
    jnfrlews@yahoo.com
The message originating IP was 68.142.206.41 The message recipients were
XXXXXXXXXXXXX
The message was titled China and Human Rights The message date was Mon, 11 Jan 2010 19:31:56 -0800 (PST) The message identifier was <54825.40062.qm@web113916.mail.gq1.yahoo.com>
attach/5963841_3X_PM5_EMS_MA-PDF__ChinaHR.pdf: Infected: Exploit.Win32.Pidief.bxf [AVP]


Virustotal
http://www.virustotal.com/analisis/b0c7da5ae8e22caeed88008c7847927a19fec7dd659746f6a124b08e3f95547b-1263277481

Result: 13/40 (32.5%)
AntiVir    7.9.1.134    2010.01.11    HTML/Silly.Gen
Antiy-AVL    2.0.3.7    2010.01.11    Exploit/Win32.Pidief
Authentium    5.2.0.5    2010.01.12    PDF/UtlPtf.B!Camelot
Avast    4.8.1351.0    2010.01.11    JS:Pdfka-ME
BitDefender    7.2    2010.01.12    Exploit.PDF-JS.Gen
eSafe    7.0.17.0    2010.01.11    PDF.Exploit
F-Secure    9.0.15370.0    2010.01.12    Exploit.PDF-JS.Gen
GData    19    2010.01.12    Exploit.PDF-JS.Gen
Kaspersky    7.0.0.125    2010.01.12    Exploit.Win32.Pidief.bxf
McAfee-GW-Edition    6.8.5    2010.01.12    Script.Silly.Gen
Sophos    4.49.0    2010.01.12    Troj/PDFJS-BX
Sunbelt    3.2.1858.2    2010.01.12    Exploit.PDF.Pidief (v)
VirusBuster    5.0.21.0    2010.01.11    JS.BOFExploit.Gen
Additional information
File size: 119239 bytes
MD5...: aaf477af8cfb73c6bd9945c5be403fe9


Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=aaf477af8cfb73c6bd9945c5be403fe9&type=js
Adobe getIconStack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab objectCVE-2009-0927

Update January 18, 2010 
jsunpack
Even better results were produced and submitted by Blake (thank you, Blake) using his  jsunpack tool - see  http://jsunpack.blogspot.com.  Utilprintf CVE-2008-2992 was detected in addition to CollabgetIcon CVE-2009-0927.
jsunpack-n$ ./jsunpack-n.py ChinaHR.pdf -V
check line 1371
Processing ChinaHR.pdf
[malicious:10] [PDF] ChinaHR.pdf
       info: [decodingLevel=0] found JavaScript
       info: [decodingLevel=0] decoded 6269 bytes (./files/decoding_
257729096ea832ff72e7365e34062d183d69f2fe)
       malicious: Utilprintf CVE-2008-2992 detected
       malicious: CollabgetIcon CVE-2009-0927 detected
       info: [decodingLevel=1] found JavaScript
       info: saved original parsed JavaScript to ./files/veryverbose_
257729096ea832ff72e7365e34062d183d69f2fe
       info: Decoding option app.viewerVersion=8.0,    4012 bytes
       info: Decoding option app.viewerVersion= and app.viewerVersion=9.1,     0 bytes
       info: [decodingLevel=1] decoded 4012 bytes (./files/decoding_
93aa0a7dc84a9b7ef6fe87912af5481a0d6a9f4d)
       suspicious: Warning detected //warning CVE-NO-MATCH Shellcode NOP len 9999 //warning CVE-NO-MATCH Shellcode NOP len 506 //warning CVE-NO-MATCH Shellcode NOP len 297 //warning CVE-NO-MATCH Shellcode NOP len 261833
       malicious: shellcode of length 565/295 (./files/shellcode_
2b5537e1a69fa16a8c625e0087023c9506002d7e)
       malicious: shellcode of length 551/277 (./files/shellcode_
e9f9df40fb0abdc9c6b119423800ca9d0583411c)
       info: [2] no JavaScript
       info: [file] saved ChinaHR.pdf to (./files/original_
074517645ec0b7e50bc788910dda51c0e9dcd889)

[file] created ./files/decoding_
257729096ea832ff72e7365e34062d183d69f2fe from ChinaHR.pdf
[file] created ./files/veryverbose_
257729096ea832ff72e7365e34062d183d69f2fe from ChinaHR.pdf
[file] created ./files/decoding_
93aa0a7dc84a9b7ef6fe87912af5481a0d6a9f4d from ChinaHR.pdf
[file] created ./files/shellcode_
2b5537e1a69fa16a8c625e0087023c9506002d7e from ChinaHR.pdf
[file] created ./files/shellcode_
e9f9df40fb0abdc9c6b119423800ca9d0583411c from ChinaHR.pdf
[file] created ./files/original_
074517645ec0b7e50bc788910dda51c0e9dcd889 from ChinaHR.pdf



Friday, November 6, 2009

Nov.6 PDF attack. Obama visit Asia from [username]098@gmail.com Nov 6, 2009 8:38:57 AM

Links updated: Jan 18, 2023

Download. Email me if you need the password


Possible MalWare 'Exploit/Zordle.gen' found in '5963792_3X_PM5_EMS_MA-PDF__Obama=20visit=20Asia.pdf'. Heuristics score: 201
From: "[REMOVED]" [mailto:098@gmail.com
Sent: Friday, November 6, 2009 8:38:57 AM GMT -05:00 US/Canada Eastern
Subject: Obama's visit to Asia


Dear Colleagues,


With the upcoming Obama's visit to Asia, please find the attached paper for your kind reference.
Should you have any questions, please contact me.
Best regards,
--
signature here [REMOVED]

File Obama_visit_Asia.pdf received on 2009.11.06 18:05:36 (UTC)

Current status: finished
Result: 4/41 (9.76%)

AntivirusVersionLast UpdateResult
a-squared4.5.0.412009.11.06-
AhnLab-V35.0.0.22009.11.06-
AntiVir7.9.1.592009.11.06-
Antiy-AVL2.0.3.72009.11.05-
Authentium5.2.0.52009.11.06PDF/Pidief.O
Avast4.8.1351.02009.11.06-
AVG8.5.0.4232009.11.06-
BitDefender7.22009.11.06Exploit.PDF-JS.Gen
CAT-QuickHeal10.002009.11.06-
ClamAV0.94.12009.11.06-
Comodo28622009.11.06-
DrWeb5.0.0.121822009.11.06-
eSafe7.0.17.02009.11.05-
eTrust-Vet35.1.71072009.11.06-
F-Prot4.5.1.852009.11.06-
F-Secure9.0.15370.02009.11.04Exploit.PDF-JS.Gen
Fortinet3.120.0.02009.11.06-
GData192009.11.06Exploit.PDF-JS.Gen
IkarusT3.1.1.74.02009.11.06-
Jiangmin11.0.8002009.11.06-
K7AntiVirus7.10.8902009.11.06-
Kaspersky7.0.0.1252009.11.06-
McAfee57932009.11.05-
McAfee+Artemis57942009.11.06-
McAfee-GW-Edition6.8.52009.11.06-
Microsoft1.52022009.11.06-
NOD3245802009.11.06-
Norman6.03.022009.11.06-
nProtect2009.1.8.02009.11.06-
Panda10.0.2.22009.11.05-
PCTools7.0.3.52009.11.06-
Prevx3.02009.11.06-
Rising21.54.44.002009.11.06-
Sophos4.47.02009.11.06-
Sunbelt3.2.1858.22009.11.06-
Symantec1.4.4.122009.11.06-
TheHacker6.5.0.2.0622009.11.05-
TrendMicro9.0.0.10032009.11.06-
VBA323.12.10.112009.11.06-
ViRobot2009.11.6.20252009.11.06-
VirusBuster4.6.5.02009.11.06-


File
Obama visit Asia.pdf
MD533aa28b079b33c1609f9096ee78e73c8
Analysis Started2009-11-06 12:10:45
Report Generated2009-11-06 12:10:53
Jsand version1.03.02

Detection results

DetectorResult
Jsand 1.03.02malicious

Exploits

NameDescriptionReference
Adobe Collab overflowMultiple Adobe Reader and Acrobat buffer overflowsCVE-2007-5659
Adobe getIconStack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab objectCVE-2009-0927