Showing posts with label CVE-2009-3129. Show all posts
Showing posts with label CVE-2009-3129. Show all posts
Thursday, October 27, 2011
Tuesday, March 29, 2011
Mar 29 CVE-2009-3129 XLS An Interview Request from a Columbia University Student
Common Vulnerabilities and Exposures (CVE)number
CVE-2009-3129 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."
Just a quick post without any analysis. Have fun.
General File Information
File Lybia.xls
MD5 7795F3C874677C8D95D070D7D40725ADFile size : 7e0e69aff159f8bb31c4e5c62228c952d3ae1fd2
Type: XLS
Distribution: Email attachment
Download
Original Message
From: Steve Perry [mailto:steve.e.perry@gmail.com]
Sent: Tuesday, March 29, 2011 3:52 AM
To:XXXXXXXXXXXXXXX
Subject: An Interview Request from a Columbia University Student
Dear Sir,
My name is Steve Perry, and I am a student at the Columbia University Graduate School of Journalism.I was assigned to focus on current conflict in Libya and was demanded to publish it in a variety of news media outlets, which is a demand for graduation.
I learn you from the following links.
XXXXXXXXXXXXXXXXXXXXXXXXX
You are a famous expert on Middle East problems, so I request to interview your. I would be honored if you receive my interview. I have made an excel diagram including questions. I hope that when you are free, you can fill in the diagram and send it back to me. Thanks very much!
Sincerely,
Steve Perry
Message Headers
Gmail :(Received: (qmail 32598 invoked from network); 29 Mar 2011 07:52:31 -0000
Received: from mail-ww0-f67.google.com (HELO mail-ww0-f67.google.com) (74.125.82.67)
by 29 Mar 2011 07:52:31 -0000
Received: by wwa36 with SMTP id 36so738671wwa.6
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=gamma;
h=domainkey-signature:mime-version:date:message-id:subject:from:to
:content-type;
bh=9+Kwinch+3AeawaoEuQ3RtWBovUsLb0jm49x9OgIWYo=;
b=SQdWqICrXhvehS3/U1o9etl84hC3Wq9SEcaiVOGJd40mTFWwunPj6aq4LocEmdRjGC
eZCsghb/5uT74cuVjf4yWI4IEhNIxDF4g46aAH2vzDk4u/DKqNmXuH/t4jYYAdsExmhO
G16W3iTR8jYQOeZqIu+XYXosOs/Mpv4VHxq+I=
DomainKey-Signature: a=rsa-sha1; c=nofws;
d=gmail.com; s=gamma;
h=mime-version:date:message-id:subject:from:to:content-type;
b=JxFV5kH+bjtpaW14GKTeoFxH4s5Pai3QJmQrQnUmP5RcMQmDTXFvzgA7sOOcPxtmlo
0HeKcEAqZqh+MboRce6YsfRrama3ZhVPzqQoqhDovYzWUqkK0TgzaE8LvebZxaYEMP0D
9KUb8Pt1uQEukmWxdtZabPIkKKBTkPNOjNQjw=
MIME-Version: 1.0
Received: by 10.216.68.85 with SMTP id k63mr2841503wed.35.1301385149026; Tue,
29 Mar 2011 00:52:29 -0700 (PDT)
Received: by 10.216.166.84 with HTTP; Tue, 29 Mar 2011 00:52:28 -0700 (PDT)
Date: Tue, 29 Mar 2011 15:52:28 +0800
Message-ID:
Subject: An Interview Request from a Columbia University Student
From: Steve Perry
To: xxxxxxxxxxxxxxxxx
Content-Type: multipart/mixed; boundary="000e0ce0b1ba86156e049f9a5758"
Automated Scans
File name:Libya.xlshttp://www.virustotal.com/file-scan/report.html?id=b7949a6ac1f2bdf0010423c77740680e396f6234658b1c7574c576e8e7211c79-1301435181
Submission date:2011-03-29 21:46:21 (UTC)
ClamAV 0.96.4.0 2011.03.29 BC.XLS.Exploit.CVE_2009_3129
Commtouch 5.2.11.5 2011.03.24 MSExcel/Dropper.B!Camelot
Jiangmin 13.0.900 2011.03.29 Heur:Exploit.CVE-2009-3129
McAfee 5.400.0.1158 2011.03.29 Exploit-MSExcel.u
McAfee-GW-Edition 2010.1C 2011.03.29 Heuristic.BehavesLike.Exploit.X97.CodeExec.FFOD
Microsoft 1.6702 2011.03.29 Exploit:Win32/CVE-2009-3129
Sophos 4.64.0 2011.03.29 Troj/DocDrop-S
TrendMicro 9.200.0.1012 2011.03.29 TROJ_EXLDROP.SM
TrendMicro-HouseCall 9.200.0.1012 2011.03.29 TROJ_EXLDROP.SM
MD5 : 7795f3c874677c8d95d070d7d40725ad
Monday, March 28, 2011
Mar 25-28 CVE-2009-3129 XLS LES Request or Lybia Crisis from bran343@yahoo.com
Common Vulnerabilities and Exposures (CVE)number
CVE-2009-3129 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."
Just a quick post without any analysis. Have fun.
General File Information
File CTF 2011 (MF).xls or BBC Monitoring report
MD5 b4c83c1bfa52e8606ddc306625938c21
File size : 65559 bytes
Type: XLS
Distribution: Email Attachment
Download
Original Message
From: Brandy R [mailto:bran343@yahoo.com]Sent: Friday, March 25, 2011 5:26 AM
Subject: Fw: LES Request
Good morning,
Please find attached the LES's you requested.
Thank you and have a good day,
Christina Donald
Contractor, MPSC Systems Analyst ARNG Financial Services Center NGB -ARC-F
ATTN: NGB-ARC-F (Column 118D)
Finance Support Team Indianapolis
1-877-ARNGPAY (1-877-276-4729)
FAX CML 317-510-7017
EMAIL 2 Libya crisis
From: Brandy R
[mailto:bran343@yahoo.com]
Sent: Monday, March 28, 2011 9:34 AM
Subject: Libya crisis
Sent: Monday, March 28, 2011 9:34 AM
Subject: Libya crisis
FYI.
Message Headers
EMAIL 1 Fw: LES RequestReceived: (qmail 5543 invoked from network); 25 Mar 2011 09:26:12 -0000
Received: from web120112.mail.ne1.yahoo.com (HELO web120112.mail.ne1.yahoo.com) (98.138.85.159)
by XXXXXXXXXXXXXXXXXXwith SMTP; 25 Mar 2011 09:26:12 -0000
Received: (qmail 27995 invoked by uid 60001); 25 Mar 2011 09:26:12 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1301045172; bh=Q62Ncyt0FmiR48qzSD2tYeVDQS315MhWUx3E6d4ifJE=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=X2I4ntxH/Fnul07T0st7CxQxfEX5Z6WewIv4veR5FX6ZKDioiQCxxLmvlFR/nRcScQgUWImSHirG2jMFJDig3Lp3urcsL1nRW14a0uo6cLySG+0KGvUxErwQfOPanoimt6cFe3T4wb+/gZLHKp7rpdEp2FCupPEYs+Dy4QkIbLg=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type;
b=yEOAl0r6EEbTisJcFejV8CFR38jDRwyX/JEMmQCtD0C//+gadqMg1lSADpI8/KQieDqj5/U50GVuY26xGBA3XB0LstVa88F9ib1UiB53eLB9+7+5iye3vJa3TlZHOvw56KMsD93wp4OUnn9KWGQEyEvsXyzV5ilQK9KmjdCW0x0=;
Message-ID: <126300.8410.qm@web120112.mail.ne1.yahoo.com>
X-YMail-OSG: OFUzx_AVM1n91t0zEacsTpDPyCacKf2bDHKoqB6Vn3hPfTd
IqUqiUZjNAJvjU.tBh7Y08mchb1DO6XwlWqlesWY6RC1xTnjPd16nUJfGWwR
Tuc9T.IQ3FpvpU0JBRq_l6KbOgoSsEVKnJmkkbrAZiNnN2Rt.4Ly9h4H.ZWP
LLFpLCn_yKWiQmmaTUXHNS4JTcJ_rU3VnM5Df3CT1HA8Y_nrHrMhWI5m3F46
tFQJvqGN0cORcXWmMhaQf8Rpikw7BY1uTWAd5S8Akf..VeQyvCrFedOPa3iV
cdC9kTJYEuZj4.x_6wdAcgem9V0AD8K4pXrMprRdlC.cjzCoFPIXgJQyzTcQ
IDMF3DDktcbnLDERPCsU3RgeXtQJZWVwwcqzu3NOxiOmt3IBYaVSUsUKl
Received: from [117.88.250.185] by web120112.mail.ne1.yahoo.com via HTTP; Fri, 25 Mar 2011 02:26:11 PDT
X-Mailer: YahooMailRC/559 YahooMailWebService/0.8.109.295617
Date: Fri, 25 Mar 2011 02:26:11 -0700
From: Brandy R
Subject: Fw: LES Request
To: undisclosed recipients: ;
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-422978493-1301045171=:8410"
EMAIL 2 Libya crisis
Received: (qmail 31482 invoked from network); 28 Mar 2011 13:33:54 -0000
Received: from web120109.mail.ne1.yahoo.com (HELO web120109.mail.ne1.yahoo.com) (98.138.85.156)
by XXXXXXXXXXXXXXXXXXXX with SMTP; 28 Mar 2011 13:33:54 -0000
Received: (qmail 21672 invoked by uid 60001); 28 Mar 2011 13:33:53 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1301319233; bh=KYu2+ZnqxcpYMv5Jjh4esqvHpQ0m1JZbZASUr8Yt8y0=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=HLo1/STzZ10/E7dyLoxHfdvAdRbkLoNYvn9FMIltVGVjIK7vuskv65yQGO2fkGSnCIC7modL5Doxocc0bJEBKDgBAS0yZ/YBoM5w3GFZYdlboS+q5rr6lU0u14vSFAPGBXzoTtiAybhKeR7q5nUzu3926eCuSq0scs4BHN4JAP0=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type;
b=zJnVrp3C96n4JIp+/JrjPKMe+6V/FIUqAkF9W/X6PLPvwkTY687N00JS3fUQQg1Xfv6QrROmVJYqZqzzYqd0nsy7LWnl08HsXxa1vuQezTH8Tw5c2X6l5u7GdHPMNX9d0k6ifYaypGcN8GuWzSaR83EourWpARC3nHtLFobwFZU=;
Message-ID: <392361.59989.qm@web120109.mail.ne1.yahoo.com>
X-YMail-OSG: _o26bK0VM1kBRio8SdKmAGN2J9.AjMCRjJwMgZz3m5sgukn
kIjR.Bkmhk7uNNOdN7FD2sCVdKC2zdHC.LaIDIPoHk.LUlvwjfcFa_HR4jEJ
ep7vem6mDGvEMfsZRizMV.QwJ9JBnHc3N4a.4h.5Z4oBnpmhYhJQ0yI6A.Rw
KXH6WzOHEYDg3nIjRjmbT1pieLwUAoBErZ9_ynJ97G1ZVK2uXmG7bA0bRGwc
D2X_Z335W_0gHNJm2IBsC34Wo5qeRvR.i4Bb6LUhkzGFadB7Y0pQObaqumW.
SI2jy2na7kgoidxSlAiVkSzk.vL4Mf2DfO.wTW6l_k9P9xjPBEJkEcd0mt5t
_KLaw5bxapbg-
Received: from [117.88.171.49] by web120109.mail.ne1.yahoo.com via HTTP; Mon, 28 Mar 2011 06:33:52 PDT
X-Mailer: YahooMailRC/559 YahooMailWebService/0.8.109.295617
Date: Mon, 28 Mar 2011 06:33:52 -0700
From: Brandy R
Subject: Libya crisis
To: undisclosed recipients: ;
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-993720929-1301319232=:59989"
Received: from web120109.mail.ne1.yahoo.com (HELO web120109.mail.ne1.yahoo.com) (98.138.85.156)
by XXXXXXXXXXXXXXXXXXXX with SMTP; 28 Mar 2011 13:33:54 -0000
Received: (qmail 21672 invoked by uid 60001); 28 Mar 2011 13:33:53 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1301319233; bh=KYu2+ZnqxcpYMv5Jjh4esqvHpQ0m1JZbZASUr8Yt8y0=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=HLo1/STzZ10/E7dyLoxHfdvAdRbkLoNYvn9FMIltVGVjIK7vuskv65yQGO2fkGSnCIC7modL5Doxocc0bJEBKDgBAS0yZ/YBoM5w3GFZYdlboS+q5rr6lU0u14vSFAPGBXzoTtiAybhKeR7q5nUzu3926eCuSq0scs4BHN4JAP0=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type;
b=zJnVrp3C96n4JIp+/JrjPKMe+6V/FIUqAkF9W/X6PLPvwkTY687N00JS3fUQQg1Xfv6QrROmVJYqZqzzYqd0nsy7LWnl08HsXxa1vuQezTH8Tw5c2X6l5u7GdHPMNX9d0k6ifYaypGcN8GuWzSaR83EourWpARC3nHtLFobwFZU=;
Message-ID: <392361.59989.qm@web120109.mail.ne1.yahoo.com>
X-YMail-OSG: _o26bK0VM1kBRio8SdKmAGN2J9.AjMCRjJwMgZz3m5sgukn
kIjR.Bkmhk7uNNOdN7FD2sCVdKC2zdHC.LaIDIPoHk.LUlvwjfcFa_HR4jEJ
ep7vem6mDGvEMfsZRizMV.QwJ9JBnHc3N4a.4h.5Z4oBnpmhYhJQ0yI6A.Rw
KXH6WzOHEYDg3nIjRjmbT1pieLwUAoBErZ9_ynJ97G1ZVK2uXmG7bA0bRGwc
D2X_Z335W_0gHNJm2IBsC34Wo5qeRvR.i4Bb6LUhkzGFadB7Y0pQObaqumW.
SI2jy2na7kgoidxSlAiVkSzk.vL4Mf2DfO.wTW6l_k9P9xjPBEJkEcd0mt5t
_KLaw5bxapbg-
Received: from [117.88.171.49] by web120109.mail.ne1.yahoo.com via HTTP; Mon, 28 Mar 2011 06:33:52 PDT
X-Mailer: YahooMailRC/559 YahooMailWebService/0.8.109.295617
Date: Mon, 28 Mar 2011 06:33:52 -0700
From: Brandy R
Subject: Libya crisis
To: undisclosed recipients: ;
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-993720929-1301319232=:59989"
Sender
Sender EMAIL 2 Fw: LES Request117.88.250.185Hostname: 185.250.88.117.broad.nj.js.dynamic.163data.com.cn
ISP: CHINANET jiangsu province network
Organization: CHINANET jiangsu province network
Country: China
State/Region: Jiangsu
Sender EMAIL 1 Libya crisis
117.88.171.49
Hostname: 49.171.88.117.broad.nj.js.dynamic.163data.com.cn
ISP: CHINANET jiangsu province network
Organization: CHINANET jiangsu province network
Country: China
State/Region: Jiangsu
City: Nanjing
ISP: CHINANET jiangsu province network
Organization: CHINANET jiangsu province network
Country: China
State/Region: Jiangsu
City: Nanjing
Automated Scans
File name:CTF 2011 (MF).xls
http://www.virustotal.com/file-scan/report.html?id=4e88204771da198cd0a8a77741d927e0662a415c52e83b1fd7b696b97ca21f3c-1301454466
Submission date:2011-03-30 03:07:46 (UTC)
6/ 41 (14.6%)
ClamAV 0.96.4.0 2011.03.30 BC.XLS.Exploit.CVE_2009_3129
Jiangmin 13.0.900 2011.03.29 Heur:Exploit.CVE-2009-3129
McAfee 5.400.0.1158 2011.03.30 Exploit-MSExcel.u
McAfee-GW-Edition 2010.1C 2011.03.29 Exploit-MSExcel.u
Microsoft 1.6702 2011.03.30 Exploit:Win32/CVE-2009-3129
Sophos 4.64.0 2011.03.30 Troj/DocDrop-S
MD5 : b4c83c1bfa52e8606ddc306625938c21
Submission date:2011-03-30 03:07:46 (UTC)
6/ 41 (14.6%)
ClamAV 0.96.4.0 2011.03.30 BC.XLS.Exploit.CVE_2009_3129
Jiangmin 13.0.900 2011.03.29 Heur:Exploit.CVE-2009-3129
McAfee 5.400.0.1158 2011.03.30 Exploit-MSExcel.u
McAfee-GW-Edition 2010.1C 2011.03.29 Exploit-MSExcel.u
Microsoft 1.6702 2011.03.30 Exploit:Win32/CVE-2009-3129
Sophos 4.64.0 2011.03.30 Troj/DocDrop-S
MD5 : b4c83c1bfa52e8606ddc306625938c21
SAME MD5 http://www.virustotal.com/file-scan/report.html?id=4e88204771da198cd0a8a77741d927e0662a415c52e83b1fd7b696b97ca21f3c-1301338109 File name:BBC Monitoring reports..xls Submission date:2011-03-28 18:48:29 (UTC) Result:6 /43 (14.0%) |
Thursday, July 8, 2010
Jul 8 CVE-2009-3129 XLS AIT Chairman Ray Burghardt Event Schedule
Download
15a22ac5b7ed9fd640d6220dac0b4488 AIT Chairman Ray Burghardt Event Schedule.xls as a password protected archive (contact me if you need the password)From: jennifer.tsao@gmail.com [mailto:jennifer.tsao@gmail.com]
Sent: Thursday, July 08, 2010 5:14 AM
To: XXXXXX
Subject: RE:AIT Chairman Ray Burghardt Event Schedule
Result: 14/42 (33.34%)
http://www.virustotal.com/analisis/3b283fedb486aa1cf6e2f0df630be8c383214a41f87464e2700ef07542b3c32b-1280207569
AntiVir 8.2.4.26 2010.07.26 EXP/Excel.CVE-2009-3129
Antiy-AVL 2.0.3.7 2010.07.26 Exploit/MSExcel.Agent
Authentium 5.2.0.5 2010.07.27 MSExcel/Dropper.B!Camelot
Avast 4.8.1351.0 2010.07.26 Win32:CVE-2009-3129
Avast5 5.0.332.0 2010.07.26 Win32:CVE-2009-3129
Emsisoft 5.0.0.34 2010.07.27 Exploit.Win32.CVE-2009!IK
GData 21 2010.07.27 Win32:CVE-2009-3129
Ikarus T3.1.1.84.0 2010.07.27 Exploit.Win32.CVE-2009
Kaspersky 7.0.0.125 2010.07.27 Exploit.MSExcel.Agent.z
McAfee-GW-Edition 2010.1 2010.07.27 Heuristic.BehavesLike.Exploit.X97.CodeExec.PGPG
Microsoft 1.6004 2010.07.26 Exploit:Win32/CVE-2009-3129
Norman 6.05.11 2010.07.26 ShellCode.A
TrendMicro 9.120.0.1004 2010.07.27 TROJ_EXELDROP.C
TrendMicro-HouseCall 9.120.0.1004 2010.07.27 TROJ_EXELDROP.C
Additional information
File size: 114750 bytes
MD5...: 7d97fd70f28ded26ea2448669651e562
Posted by
Mila
at
1:24 AM
0
comments
Tags:
- MS EXCEL 2003 SP3,
- MS EXCEL 2007 SP2,
- MS EXCEL 2007 SP3,
- OFFICE 2004 MAC,
- OFFICE 2008 MAC,
CVE-2009-3129
Tuesday, July 6, 2010
Jul 06 CVE-2009-3129 XLS Update Report 0702 from ycyeh@mail.moe.gov.tw
Download 0702g.xls 9b60af61854a4334967377c0d19a4af4 as a password protected archive (contact me if you need the password)
From: ycyeh [mailto:ycyeh@mail.moe.gov.tw]
Sent: Tuesday, July 06, 2010 4:00 AM
To:XXXXXXXXXXXX
Subject: 更新0702週報表
Sent: Tuesday, July 06, 2010 4:00 AM
To:XXXXXXXXXXXX
Subject: 更新0702週報表
From: ycyeh [mailto: ycyeh@mail.moe.gov.tw]Sent: Tuesday, July 06, 2010 4:00 AMTo: XXXXXXXXXXXXSubject: Update Report 0702 weeks
File 0702g.xls received on 2010.07.27 05:33:32 (UTC)
http://www.virustotal.com/analisis/3000b45d24d2f958efbba838c27c5dc7e110b0ecd53aa772a46e7c2a0093263b-1280208812
Result: 14/41 (34.15%)
AntiVir 8.2.4.26 2010.07.26 EXP/Excel.CVE-2009-3129
Antiy-AVL 2.0.3.7 2010.07.26 Exploit/Win32.CVE-2009-3129
Authentium 5.2.0.5 2010.07.27 MSExcel/Dropper.B!Camelot
Avast 4.8.1351.0 2010.07.26 Win32:CVE-2009-3129
Avast5 5.0.332.0 2010.07.26 Win32:CVE-2009-3129
Emsisoft 5.0.0.34 2010.07.27 Exploit.Win32.CVE-2009!IK
GData 21 2010.07.27 Win32:CVE-2009-3129
Ikarus T3.1.1.84.0 2010.07.27 Exploit.Win32.CVE-2009
Kaspersky 7.0.0.125 2010.07.27 Exploit.Win32.CVE-2009-3129.a
McAfee 5.400.0.1158 2010.07.27 Exploit-MSExcel.u
McAfee-GW-Edition 2010.1 2010.07.27 Heuristic.BehavesLike.Exploit.X97.CodeExec.PGPG
Microsoft 1.6004 2010.07.26 Exploit:Win32/CVE-2009-3129
Norman 6.05.11 2010.07.26 ShellCode.A
TrendMicro-HouseCall 9.120.0.1004 2010.07.27 HEUR_OLEXP.B
Additional information
File size: 104510 bytes
MD5...: 9b60af61854a4334967377c0d19a4af4
Headers
Received: from IBM-62979760B13 ([211.75.147.173])
by msr25.hinet.net (8.9.3/8.9.3) with ESMTP id PAA06994
Reply-To: ycyeh@mail.moe.gov.tw
From: "ycyeh"
To: "=?BIG5?B?tsCktqW/?="
Subject: =?BIG5?B?p/O3czA3MDK2Z7P4qu0=?=
Date: Tue, 6 Jul 2010 16:00:00 +0800
by msr25.hinet.net (8.9.3/8.9.3) with ESMTP id PAA06994
Reply-To: ycyeh@mail.moe.gov.tw
From: "ycyeh"
To: "=?BIG5?B?tsCktqW/?="
Subject: =?BIG5?B?p/O3czA3MDK2Z7P4qu0=?=
Date: Tue, 6 Jul 2010 16:00:00 +0800
ISP: CHTD, Chunghwa Telecom Co., Ltd.
Organization: Ming Siang Printing Co., Ltd.
Proxy: None detected
Type: Broadband
Assignment: Static IP
Country: Taiwan tw flag
State/Region: T'ai-pei
City: Taipei
Posted by
Mila
at
1:42 AM
0
comments
Tags:
- MS EXCEL 2003 SP3,
- MS EXCEL 2007 SP2,
- MS EXCEL 2007 SP3,
- OFFICE 2004 MAC,
- OFFICE 2008 MAC,
CVE-2009-3129
Wednesday, June 30, 2010
Jun 30 CVE-2009-3129 XLS Mission to China Permanent Contact info
Download 15a22ac5b7ed9fd640d6220dac0b4488 Permanent Contact info.xls as a password protected archive (contact me if you need the password)From: Gary Crowley [mailto:gcgarycrowley@yahoo.com]
Sent: Wednesday, June 30, 2010 8:56 PM
To: gcgarycrowley@yahoo.com
Subject: Fw: U.S. Mission to China Permanent Contact info
Dear all
Attached is U.S. Mission to China Permanent Contact.
Result: 8/42 (19.05%)
http://www.virustotal.com/analisis/68809148ea164e7e9c605e51740e229160540c301c1148d5a9732cd62a43022c-1280205402
Antivirus Version Last Update Result
AntiVir 8.2.4.26 2010.07.26 EXP/Excel.CVE-2009-3129
Authentium 5.2.0.5 2010.07.27 MSExcel/Dropper.B!Camelot
Emsisoft 5.0.0.34 2010.07.27 Exploit.Win32.CVE-2009!IK
Ikarus T3.1.1.84.0 2010.07.27 Exploit.Win32.CVE-2009
Microsoft 1.6004 2010.07.26 Exploit:Win32/CVE-2009-3129
http://www.virustotal.com/analisis/68809148ea164e7e9c605e51740e229160540c301c1148d5a9732cd62a43022c-1280205402
Antivirus Version Last Update Result
AntiVir 8.2.4.26 2010.07.26 EXP/Excel.CVE-2009-3129
Authentium 5.2.0.5 2010.07.27 MSExcel/Dropper.B!Camelot
Emsisoft 5.0.0.34 2010.07.27 Exploit.Win32.CVE-2009!IK
Ikarus T3.1.1.84.0 2010.07.27 Exploit.Win32.CVE-2009
Microsoft 1.6004 2010.07.26 Exploit:Win32/CVE-2009-3129
Norman 6.05.11 2010.07.26 ShellCode.M
TrendMicro 9.120.0.1004 2010.07.27 TROJ_DROPPER.QRX
TrendMicro-HouseCall 9.120.0.1004 2010.07.27 TROJ_DROPPER.QRX
Additional information
File size: 56714 bytes
MD5...: 15a22ac5b7ed9fd640d6220dac0b4488
TrendMicro 9.120.0.1004 2010.07.27 TROJ_DROPPER.QRX
TrendMicro-HouseCall 9.120.0.1004 2010.07.27 TROJ_DROPPER.QRX
Additional information
File size: 56714 bytes
MD5...: 15a22ac5b7ed9fd640d6220dac0b4488
Headers
Received: from [180.150.229.29] by web120112.mail.ne1.yahoo.com via HTTP; Wed, 30 Jun 2010 17:56:09 PDT
X-Mailer: YahooMailClassic/11.1.4 YahooMailWebService/0.8.104.274457
Date: Wed, 30 Jun 2010 17:56:09 -0700
From: Gary Crowley
Subject: Fw: U.S. Mission to China Permanent Contact info
To: gcgarycrowley@yahoo.com
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-415109960-1277945769=:30240"
netnum: 180.150.224.0 - 180.150.231.255
netname: EHOSTIDC
country: KR
admin-c: JK1606-AP
tech-c: JK1606-AP
status: Allocated Portable
remarks: www.ehostidc.co.kr
mnt-by: MNT-KRNIC-AP
mnt-lower: MNT-KRNIC-AP
changed: XXXXXXXXXX@apnic.net 20090909
source: APNIC
person: Jinyoung Lee
nic-hdl: JK1606-AP
e-mail: XXXXXXX@ehostidc.co.kr
address: Newticastle Geumcheon-gu Gasan-dong Seoul
phone: +82-2-6277-3316
fax-no: +82-2-6277-3311
country: KR
changed: XXXXXXXXXX@nida.or.kr 20090512
mnt-by: MNT-KRNIC-AP
source: APNIC
inetnum: 180.150.224.0 - 180.150.231.255
netname: EHOSTIDC-KR
Posted by
Mila
at
12:59 AM
0
comments
Tags:
- MS EXCEL 2003 SP3,
- MS EXCEL 2007 SP2,
- MS EXCEL 2007 SP3,
- OFFICE 2004 MAC,
- OFFICE 2008 MAC,
CVE-2009-3129
Friday, May 28, 2010
May 28 CVE-2009-3129 XLS for office 2002-2007 with fud keylogger EIDHR from david@humanright-watch.org
Update:
Noticed an ineresting post by Nart Villeneuve (Internet Censorship
Explorer) regarding this malware and decided to update and resurrect the
post
Download 4f681733fd9e473c09f967fa87c9faef EIDHR.xls and all the files described below as a password protected archive (contact me if you need the password)From: david@humanright-watch.org [mailto:david@humanright-watch.org] On Behalf Of ??
Sent: Friday, May 28, 2010 2:31 AM
To: XXXXXX
Subject: 關於EIDHR項目
諸位
關於EIDHR歐洲人權項目我詳細咨詢了歐盟的朋友,爲了使申請能順利通過,還須補充一些資料,具體資料項目和内容概要都附在後面了,祝各位順利。
張英
From: SHARPE Simon (RELEX-BEIJING)
Sent: Monday, May 24, 2010 6:15 PM
Subject: FW: EIDHR 项目征求书
大家好:
欧盟现在有一个EIDHR的项目征求。项目的目的在于资助推动人权的项目,涵盖的领域很广泛。大家可以跟其他感兴趣的朋友分享这个信息。
项目活动的主题
具有以下主题的计划书会受到优先考虑:
1. 思考自由,宗教自由和信仰自由的权利
2. 言论和表达的自由,包括艺术和文化的表达,信息和沟通的权利,包括媒体自由,反对审查和网络自由
3. 和平集会和结社自由的权利,包括建立和参加工会的权利
4. 在一国境内自由行动的权利,离开任何国家(包括本国)和回到本国的权利
项目活动
项目活动可以包括从监督,倡导,公开信息,提高意识到能力建设,培训以及与利益攸关者对话等一系列形式。最终目标都是为了提高所在国的公民社会组织的自主权。
项目的资助总额最低为15万欧元,最高为120万欧元。项目的延续时间应不少于18个月,但不超过3年。比较重要的是附件中的项目指导,首先需要提交一个简短的项目概念书,申请的最后期限是6月15日。项目申请时要填写链接中的Annex A,B,C 等表格。
申请有两种方法:
1. 通过PADOR系统注册申请。http://ec.europa.eu/europeaid/onlineservices/pador/index_en.htm
2. 或将申请所需的项目概念书以及表格A,B,C寄往如下地址:
邮寄地址
European Commission
EuropeAid Co-operation Office
Unit F4 – Finances, Contracts and Audit for thematic budget lines
Call for Proposals Sector
Office: L-41 03/154
B - 1049 Brussels
BELGIUM
快递地址
European Commission
EuropeAid Cooperation Office
Unit F4 – Finances, Contracts and Audit for thematic budget lines
Call for Proposals Sector
Office: L-41 03/154
Central Mail Service
Avenue du Bourget 1
B-1140 Brussels (Evère)
BELGIUM
关于项目的具体内容在https://webgate.ec.europa.eu/europeaid/onlineservices/index.cfm?do=publi.welcome&nbPubliList=15&orderby=upd&orderbyad=Desc&searchtype=RS&aofr=126352
如果需要更多的信息,请随时与我们联系。谢谢!
欧盟驻华代表团夏明
See machine translation in the end
Headers
Received: (qmail 3230 invoked from network); 28 May 2010 06:31:58 -0000
Received: from static-ip-251-116-134-202.rev.dyxnet.com (HELO mx02.diaocha8.com) (202.134.116.251) by XXXXXXXXXXXXXXXXXXX with SMTP; 28 May 2010 06:31:58 -0000
Received: from sppfszwr (unknown [180.98.74.10])
by mx02.diaocha8.com (EMOS V1.5 (Postfix)) with ESMTPA id 37B71109A81
for
Reply-To:
Sender: david@humanright-watch.org
Message-ID:
From: =?utf-8?B?5by16Iux?=
To: XXXXXXXXXXXXXXX
Subject: =?utf-8?B?6Zec5pa8RUlESFLpoIXnm64=?=
Date: Fri, 28 May 2010 14:31:10 +0800
Received: from static-ip-251-116-134-202.rev.dyxnet.com (HELO mx02.diaocha8.com) (202.134.116.251) by XXXXXXXXXXXXXXXXXXX with SMTP; 28 May 2010 06:31:58 -0000
Received: from sppfszwr (unknown [180.98.74.10])
by mx02.diaocha8.com (EMOS V1.5 (Postfix)) with ESMTPA id 37B71109A81
for
Reply-To:
Sender: david@humanright-watch.org
Message-ID:
From: =?utf-8?B?5by16Iux?=
To: XXXXXXXXXXXXXXX
Subject: =?utf-8?B?6Zec5pa8RUlESFLpoIXnm64=?=
Date: Fri, 28 May 2010 14:31:10 +0800
Hostname: 180.98.74.10
ISP: CHINANET jiangsu province network
Organization: CHINANET jiangsu province network
State/Region: Jiangsu
City: Suzhou
-
File EIDHR.xls received on 2010.06.02 04:13:50 (UTC)
http://www.virustotal.com/analisis/8b8960a855603393190152439c64ac9fd16655b304d472ecb83422900369a266-1275452030
Result: 17/41 (41.47%)
a-squared 5.0.0.26 2010.06.02 Trojan-Dropper.MSExcel.Agent!IK
AntiVir 8.2.1.242 2010.06.01 TR/Drop.MSExcel.Agent.BC
Antiy-AVL 2.0.3.7 2010.06.01 Trojan/MSExcel.Agent
Authentium 5.2.0.5 2010.06.02 MSExcel/Dropper.B!Camelot
BitDefender 7.2 2010.06.02 Exploit.D-Encrypted.Gen
F-Secure 9.0.15370.0 2010.06.02 Exploit.D-Encrypted.Gen
GData 21 2010.06.02 Exploit.D-Encrypted.Gen
Ikarus T3.1.1.84.0 2010.06.02 Trojan-Dropper.MSExcel.Agent
Jiangmin 13.0.900 2010.05.31 Heur:Exploit.CVE-2009-3129
Kaspersky 7.0.0.125 2010.06.02 Trojan-Dropper.MSExcel.Agent.bc
McAfee-GW-Edition 2010.1 2010.06.02 Heuristic.BehavesLike.Exploit.X97.CodeExec.EBEB
Norman 6.04.12 2010.06.01 ShellCode.B
nProtect 2010-06-01.02 2010.06.01 Exploit.D-Encrypted.Gen
PCTools 7.0.3.5 2010.06.02 HeurEngine.MaliciousExploit
Symantec 20101.1.0.89 2010.06.02 Bloodhound.Exploit.306
TrendMicro 9.120.0.1004 2010.06.02 TROJ_MDROPR.MRV
TrendMicro-HouseCall 9.120.0.1004 2010.06.02 TROJ_MDROPR.MRV
Additional information
File size: 64166 bytes
MD5...: 4f681733fd9e473c09f967fa87c9faef
Excel successfully opens, displaying hello, and a Chinese font set as default. The properties show that it was created on a Lenovo (Beijing) Limited laptop.
Files created
- D52EF63FDC5C5452D9DA23BD6D4BF0F5 %userprofile%\Local Settings\Temp\1001.tmp11kb 0/41 Virustotal
- D52EF63FDC5C5452D9DA23BD6D4BF0F5 C:\WINDOWS\ntshrui.dll 11kb 0/41 Virustotal
- A363ABE09A44176386C50EE887359270 %userprofile%\Local Settings\Temp\set.xls 17kb -clean spreadsheet
you see above
Posted by
Mila
at
8:02 AM
2
comments
Tags:
- MS EXCEL 2007 SP2,
- MS EXCEL 2003 SP3,
- MS EXCEL 2007 SP2,
- MS EXCEL 2007 SP3,
- OFFICE 2004 MAC,
- OFFICE 2008 MAC,
CVE-2009-3129
Thursday, May 13, 2010
May 13 CVE-2009-3129 XLS General Hospital service from taup@msa.hinet.net
CVE-2009-3129 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."
Download 61A29B7D8A6C3A03A884F2F64BE5CA21 ATT42396.zip as a password protected archive (contact me if you need the password)I have more samples of this CVE, different MD5. Email me if needed
Details 61A29B7D8A6C3A03A884F2F64BE5CA21 ATT42396.xls
From: 陳志良 [mailto:taup@msa.hinet.net]
Sent: Thursday, May 13, 2010 10:13 PM
To: XXXX
Subject: FW:三軍總醫院健康檢查中心提供健康食譜.xls
很不錯的健康食譜,多多宣傳,讓更多的臺灣民眾可以健康飲食
Sent: Thursday, May 13, 2010 10:13 PM
To: XXXX
Subject: FW:三軍總醫院健康檢查中心提供健康食譜.xls
很不錯的健康食譜,多多宣傳,讓更多的臺灣民眾可以健康飲食
From: Zhi-Liang Chen [mailto: taup@msa.hinet.net] Sent: Thursday, May 13, 2010 10:13 PM To: XXXX Subject: FW: Tri-Service General Hospital Health Examination Center provides health recipes. Xls Very good recipes, lots of publicity so that more people in Taiwan can be a healthy diet
http://www.virustotal.com/analisis/26cf5790e8b3808bb6e509fa239de93baf719ab379311c6d0d16795f25a218b6-1274269409
Result: 6/41 (14.64%)
Authentium 5.2.0.5 2010.05.19 MSExcel/Dropper.B!Camelot
Jiangmin 13.0.900 2010.05.19 Heur:Exploit.CVE-2009-3129
PCTools 7.0.3.5 2010.05.19 HeurEngine.MaliciousExploit
Symantec 20101.1.0.89 2010.05.19 Bloodhound.Exploit.306
TrendMicro 9.120.0.1004 2010.05.19 TROJ_EXELDROP.A
TrendMicro-HouseCall 9.120.0.1004 2010.05.19 TROJ_EXELDROP.A
Additional information
File size: 64512 bytes
MD5...: 61a29b7d8a6c3a03a884f2f64be5ca21
header info
Received: from msr6.hinet.net (HELO msr6.hinet.net) (168.95.4.106)
by XXXXXXXXXXXX with SMTP; 14 May 2010 02:13:35 -0000
Received: from IBM-62979760B13 (203-69-74-246.HINET-IP.hinet.net [203.69.74.246])
by msr6.hinet.net (8.9.3/8.9.3) with ESMTP id KAA15594
for XXXXX; Fri, 14 May 2010 10:13:29 +0800 (CST)
Reply-To: taup@msa.hinet.net
by XXXXXXXXXXXX with SMTP; 14 May 2010 02:13:35 -0000
Received: from IBM-62979760B13 (203-69-74-246.HINET-IP.hinet.net [203.69.74.246])
by msr6.hinet.net (8.9.3/8.9.3) with ESMTP id KAA15594
for XXXXX; Fri, 14 May 2010 10:13:29 +0800 (CST)
Reply-To: taup@msa.hinet.net
Hostname: 203-69-74-246.hinet-ip.hinet.net
ISP: CHTD, Chunghwa Telecom Co., Ltd.
Organization: Yamma Digital Technology Co., Ltd.
State/Region: T'ai-pei
ISP: CHTD, Chunghwa Telecom Co., Ltd.
Organization: Yamma Digital Technology Co., Ltd.
State/Region: T'ai-pei
Monday, May 10, 2010
May 10 CVE-2009-3129 XLS schedule of the defense industry evaluation from 0922750173@mail.ahccddi.org.tw
Download d4b98bda9c3ae0810a61f95863f4f81e ATT39755.xls and all the files described below as a password protected archive (contact me if you need the password)
From: ¤u¦X•|³ø [mailto:0922750173@mail.ahccddi.org.tw]
Sent: Monday, May 10, 2010 9:38 AM
To: XXXXXXXXXXX
Subject: 99下半年國防工業評鑑日期表
檢送99下半年國防工業評鑑日期表文件乙份,請查照!
蕭名槐 敬上
From: ¤ u | X • | ³ ø [mailto: 0922750173@mail.ahccddi.org.tw]Sent: Monday, May 10, 2010 9:38 AM
To: XXXXXXXXXXX
Subject: 99下半年國防工業評鑑日期表
檢送99下半年國防工業評鑑日期表文件乙份,請查照!
蕭名槐 敬上
Sent: Monday, May 10, 2010 9:38 AM
To: XXXXXXXXXXX
Subject: 99 in the second half schedule of the defense industry evaluation
Sincerely, Huai Hsiao
Headers
Received: (qmail 314 invoked from network); 10 May 2010 13:54:05 -0000
Received: from mailsnd3.chollian.net (HELO mailsnd3.chol.com) (203.252.1.124)
by XXXXXXXXXXXXXXXXXXXwith SMTP; 10 May 2010 13:54:05 -0000
Received: (qmail 2745 invoked from network); Mon, 10 May 2010 22:53:58 +0900 (KST)Received: from [202.65.223.202] (202.65.223.202)
by mailsnd3.chol.com with ESMTP;
Mon, 10 May 2010 22:53:58 +0900 (KST)
Message-ID: <1975e5623c$23fce32a$0ae1d8b4@0922750173212af2ce2>
From: "?u?X?|??" <0922750173@mail.ahccddi.org.tw>
To: XXXXXXXXXXXXXXXXXX
Subject: =?big5?B?OTmkVaVipn6w6qi+pHW3frX7xbKk6bTBqu0=?=
Date: Mon, 10 May 2010 21:37:50 +0800
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0009_01CAF089.0C84DC60"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5579
Received: from mailsnd3.chollian.net (HELO mailsnd3.chol.com) (203.252.1.124)
by XXXXXXXXXXXXXXXXXXXwith SMTP; 10 May 2010 13:54:05 -0000
Received: (qmail 2745 invoked from network); Mon, 10 May 2010 22:53:58 +0900 (KST)Received: from [202.65.223.202] (202.65.223.202)
by mailsnd3.chol.com with ESMTP;
Mon, 10 May 2010 22:53:58 +0900 (KST)
Message-ID: <1975e5623c$23fce32a$0ae1d8b4@0922750173212af2ce2>
From: "?u?X?|??" <0922750173@mail.ahccddi.org.tw>
To: XXXXXXXXXXXXXXXXXX
Subject: =?big5?B?OTmkVaVipn6w6qi+pHW3frX7xbKk6bTBqu0=?=
Date: Mon, 10 May 2010 21:37:50 +0800
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0009_01CAF089.0C84DC60"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5579
202.65.223.202
Hostname: static-ip-202-223-65-202.rev.dyxnet.comISP: Genesis Net Limited
Organization: Tsuen Wan
Type: Broadband
Assignment: Static IP
Country: Hong Kong
City: Central District
File ATT39755.xls received on 2010.06.03 11:27:14 (UTC)
http://www.virustotal.com/analisis/616b561b49258346ead431e34fb1925e2dbc11fb4620083efae92d7ed8e5333c-1275564434
Result: 7/41 (17.08%)
Jiangmin 13.0.900 2010.06.03 Heur:Exploit.CVE-2009-3129
Kaspersky 7.0.0.125 2010.06.03 Trojan-Dropper.MSExcel.Agent.bc
Heuristic.BehavesLike.Exploit.X97.CodeExec.FFLG
PCTools 7.0.3.5 2010.06.03 HeurEngine.MaliciousExploit
Symantec 20101.1.0.89 2010.06.03 Bloodhound.Exploit.306
TrendMicro 9.120.0.1004 2010.06.03 TROJ_EXELDROP.A
TrendMicro-HouseCall 9.120.0.1004 2010.06.03 TROJ_EXELDROP.A
Additional information
File size: 72192 bytes
MD5...: d4b98bda9c3ae0810a61f95863f4f81e
Files created
%Userprofile%\LOCALS~1\Temp\wuauclt.exe
File: wuauclt.exe Size: 31232 MD5: D037500368207625E3FFEE16C50D60A7
%Userprofile%\LOCALS~1\Temp\ ATT39755.xls
File: ATT39755.xls Size: 13824 MD5: 75B495C8324C4DCF5A0B2CFCACC47971 == clean xls filehttp://www.virustotal.com/reanalisis.html?1a15e1c3220e8d1800bb7b186e9d47f63aefd669cd0f1569a79982498d5d9ba6-1275579814
File wuauclt.exe-- received on 2010.06.02 00:43:59 (UTC)
Result: 4/41 (9.76%)
Microsoft 1.5802 2010.06.02 Backdoor:Win32/Ixeshe.A
Norman 6.04.12 2010.06.01 W32/Malware
TrendMicro 9.120.0.1004 2010.06.01 BKDR_IXESHE.SM
TrendMicro-HouseCall 9.120.0.1004 2010.06.02 BKDR_IXESHE.SM
Additional information
File size: 31232 bytes
MD5 : d037500368207625e3ffee16c50d60a7
TCP traffic to 211.78.147.220
Hostname: ll-211-78-147-220.ll.sparqnet.net
ISP: New Centry InfoComm Tech. Co., Ltd.
Organization: Lill Guan Industry co., LTD
Type: Broadband
Assignment: Static IP
Country: Taiwan
City: Taichung
Subscribe to:
Posts (Atom)











