Clicky

Pages

Monday, November 23, 2009

Nov.23 PDF attack. The three undisclosed secret in President Obama Tours Asia Nov 23, 2009 11:23 AM from jenniferf.carlson@yahoo.com

Download the malicious PDF (password protected, you have to contact me for the password)
http://www.mediafire.com/?0ozfmnnegnh


The three undisclosed secret in President Obama Tours Asia

Sent: Mon 11/23/2009 11:23 AM
From: Jennifer F. Carlson [jenniferf.carlson@yahoo.com]

fyi.

The three undisclosed secret in President Obama Tours Asia.


The message sender was
    jenniferf.carlson@yahoo.com

The message originating IP was 68.142.206.162 The message recipients were
    ouruser@ourdomain.xxx

The message was titled The three undisclosed secret in President Obama Tours Asia The message date was Mon, 23 Nov 2009 08:22:38 -0800 (PST) The message identifier was <881116.55087.qm@web111811.mail.gq1.yahoo.com>
The virus or unauthorised code identified in the email is:
F-Secure Security Platform version 1.12  build 6412 Copyright (c) 1999-2007 F-Secure Corporation. All Rights Reserved.

Scan started at Mon Nov 23 16:22:42 2009 Database version: 2009-11-23_10

attach/5963917_3X_PM5_EMS_MA-PDF__ObamaAndAsia.pdf: Infected: Exploit.SWF.Agent.ci [AVP]



Virustotal analysis

File ObamaAndAsia.pdf received on 2009.11.25 06:39:38 (UTC)

Result: 5/41 (12.2%)

Antivirus Version Last Update Result

BitDefender 7.2 2009.11.25 Trojan.SWF.HeapSpray.B
F-Secure 9.0.15370.0 2009.11.24 Trojan.SWF.HeapSpray.B
Kaspersky 7.0.0.125 2009.11.25 Exploit.SWF.Agent.ci
GData 19 2009.11.25 Trojan.SWF.HeapSpray.B
Sunbelt 3.2.1858.2 2009.11.25 Exploit.PDF-JS.Gen (v)

Wednesday, November 18, 2009

Nov.18 PDF attack. U.S. ship thwarts second pirate attack November 18, 2009.pdf Nov 18, 2009 10:38:02 AM from michael.gillenwater@dhs.gov (Spoofed sender)


Links updated: Jan 18, 2023


Download the malicious pdf (password protected, you have to contact me for the password)

Email message text

Fw: U.S. ship thwarts second pirate attack November 18, 2009
michael.gillenwater
To: Undisclosed-Recipient:;
Sent: 11/18/2009 10:38 AM
>>
>>
>>> FYI
>>>
>>>
>>> ----- Original Message -----
>>> From: "Antweiler"
>>> To:
>>> Sent: Wednesday, November 18, 2009 4:40 AM
>>> Subject:Today: U.S. ship thwarts second pirate attack

Wepawet analysis
http://wepawet.cs.ucsb.edu/view.php?hash=0b9e08970966b28ad05300038a16ba22&type=js 

Virustotal https://www.virustotal.com/gui/file/5464cfb7c8912c0dbc8b97ac342efd1b39561dba1cb47f69ee70114c7908565a/details 
Analysis report for U.S. ship thwarts second pirate attack November 18, 2009.pdf
Sample Overview
File    U.S. ship thwarts second pirate attack November 18, 2009.pdf
MD5    0b9e08970966b28ad05300038a16ba22
Analysis Started    2009-11-18 07:50:52
Report Generated    2009-11-18 07:50:57
JSAND version    1.03.02
Detection results
Detector    Result
JSAND 1.03.02    malicious

Exploits
Name    Description    Reference


Adobe Collab overflow    Multiple Adobe Reader and Acrobat buffer overflows    CVE-2007-5659

Adobe getIcon    Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object    CVE-2009-0927




Heap Spraying with Actionscript by FireEye and From Targeted PDF Attack to Backdoor in Five Stages y McAfee

Links updated: Jan 18, 2023





Excerpt
FireEye Malware Intelligence Lab
Julia Wolf @ FireEye Malware Intelligence Lab

Heap Spraying with Actionscript

Why turning off Javascript won't help this time
 Introduction


As you may have heard, there's a new Adobe PDF-or-Flash-or-something 0-day in the wild. So this is a quick note about how it's implemented, but this blog post is not going to cover any details about the exploit itself.


Background Summary


Most of the Acrobat exploits over the last several months use the, now common, heap spraying technique, implemented in Javascript/ECMAscript, a Turing complete language that Adobe thought would go well with static documents. (Cause that went so well for Postscript) (Ironically, PDF has now come full circle back to having the features of Postscript that it was trying to get away from.) The exploit could be made far far less reliable, by disabling Javascript in your Adobe Acrobat Reader.


But apparently there's no easy way to disable Flash through the UI. US-CERT recommends renaming the “%ProgramFiles%\Adobe\Reader 9.0\Reader\authplay.dll” and “%ProgramFiles%\Adobe\Reader 9.0\Reader\rt3d.dll” files. [Edit: Actually the source for this advice is the Adobe Product Security Incident Response Team (PSIRT).]


Anyway, here's why… Flash has it's own version of ECMAScript called Actionscript, and whoever wrote this new 0-day, finally did something new by implementing the heap-spray routine with Actionscript inside of Flash. More
II. http://www.avertlabs.com/research/blog/index.php/2009/09/14/from-targeted-pdf-attack-to-backdoor-in-five-stages/

McAfee Labs Blog
Excerpt
          From Targeted PDF Attack to Backdoor in Five Stages
          Monday September 14, 2009 at 12:33 pm CST
          Posted by Dennis Elser

 As reported by Adobe in July, a Flash vulnerability is being actively exploited by targeted attacks against Adobe Reader. Yes, embedding Flash movies in PDF documents is supported in Adobe Acrobat 9. The idea of allowing Flash movies to be displayed within PDFs isn’t bad if you like your documents spiced up with a bit of interactivity or training videos. From a security perspective, however, this poses yet another attack vector for criminals to take control of vulnerable systems. As history has shown, complexity and feature richness go hand in hand with remotely exploitable vulnerabilities. It is unfortunately no different with this latest PDF feature.


The exploitation of this vulnerability continues. Below are screenshots from one such malicious PDF document, discovered in a targeted attack this week. The attack contains several compressed streams and at least two embedded Flash movies. The first embedded Flash movie is clean, the second 6exploits CVE-ID 2009-1862, which causes a memory corruption and allows an attacker’s code to execute. Underneath the compression layer, JavaScript code is embedded in the PDF document. This code fills heap memory with the attacker’s shellcode. Apart from the PDF acting as an additional obfuscation layer around the exploit, the JavaScript code, once unpacked, contains another function that attempts to evade detection. More

Saturday, November 14, 2009

Hacker Magazine (Xakep - Haker #10 2009) in Russian


Links updated: Jan 18, 2023


Hacker Magazine (Xakep - Haker #10 2009)
Download pdf in Russian
















Tuesday, November 10, 2009

Nov.8 PDF attack 國防部人力司招聘「專案研究助理」 from administrators@mnd.gov.tw Sun, Nov 08, 2009 8:13 PM

Links updated: Jan 18, 2023

From: 國防部人力司 [mailto:administrators@mnd.gov.tw]
Sent: Sunday, November 08, 2009 8:13 PM
To: ouruser@ourdomain
Subject: 國防部人力司招聘「專案研究助理」
如附件所示,請 鑒核。
國防部人力司李意超敬上
地址:臺北市博愛路172號.

Approx. Translation:
Dept of Defense Manpower Division is recruiting a special research assistant
Please see attached.
Department of Defense Manpower Division
LI Yi-chao Sincerely,
Address: No. 172 Po-ai Road, Taipei.


Wepawet Analysis report for 國防部人力司招聘「專案研究助理 .pdf
Sample Overview
File 國防部人力司招聘「專案研究助理.pdf
MD5 35300c972545b9ae6efac2d24fea8b67
Analysis Started 2009-11-10 20:44:08
Report Generated 2009-11-10 20:44:18
Jsand version 1.03.02
Detection results
Detector Result
Jsand 1.03.02 malicious

Exploits

Sunday, November 8, 2009

COFEE v112

Links updated: Jan 18, 2023



COFEE - Computer forensics tool


Excerpt
What is COFEE?
COFEE has been designed to provide the investigator the ability to collect evidence from a target system
with the minimum of user interaction. After the GUI interface generates a COFEE USB device (copies all
scripts and programs), the investigator can take the device and easily insert it onto a target machine,
and begin the collection process by executing a single program.

Published by NIJ (56)


DOJ Computer forensics tool testing reports

Friday, November 6, 2009

Nov.6 PDF attack. Obama visit Asia from [username]098@gmail.com Nov 6, 2009 8:38:57 AM

Links updated: Jan 18, 2023

Download. Email me if you need the password


Possible MalWare 'Exploit/Zordle.gen' found in '5963792_3X_PM5_EMS_MA-PDF__Obama=20visit=20Asia.pdf'. Heuristics score: 201
From: "[REMOVED]" [mailto:098@gmail.com
Sent: Friday, November 6, 2009 8:38:57 AM GMT -05:00 US/Canada Eastern
Subject: Obama's visit to Asia


Dear Colleagues,


With the upcoming Obama's visit to Asia, please find the attached paper for your kind reference.
Should you have any questions, please contact me.
Best regards,
--
signature here [REMOVED]

File Obama_visit_Asia.pdf received on 2009.11.06 18:05:36 (UTC)

Current status: finished
Result: 4/41 (9.76%)

AntivirusVersionLast UpdateResult
a-squared4.5.0.412009.11.06-
AhnLab-V35.0.0.22009.11.06-
AntiVir7.9.1.592009.11.06-
Antiy-AVL2.0.3.72009.11.05-
Authentium5.2.0.52009.11.06PDF/Pidief.O
Avast4.8.1351.02009.11.06-
AVG8.5.0.4232009.11.06-
BitDefender7.22009.11.06Exploit.PDF-JS.Gen
CAT-QuickHeal10.002009.11.06-
ClamAV0.94.12009.11.06-
Comodo28622009.11.06-
DrWeb5.0.0.121822009.11.06-
eSafe7.0.17.02009.11.05-
eTrust-Vet35.1.71072009.11.06-
F-Prot4.5.1.852009.11.06-
F-Secure9.0.15370.02009.11.04Exploit.PDF-JS.Gen
Fortinet3.120.0.02009.11.06-
GData192009.11.06Exploit.PDF-JS.Gen
IkarusT3.1.1.74.02009.11.06-
Jiangmin11.0.8002009.11.06-
K7AntiVirus7.10.8902009.11.06-
Kaspersky7.0.0.1252009.11.06-
McAfee57932009.11.05-
McAfee+Artemis57942009.11.06-
McAfee-GW-Edition6.8.52009.11.06-
Microsoft1.52022009.11.06-
NOD3245802009.11.06-
Norman6.03.022009.11.06-
nProtect2009.1.8.02009.11.06-
Panda10.0.2.22009.11.05-
PCTools7.0.3.52009.11.06-
Prevx3.02009.11.06-
Rising21.54.44.002009.11.06-
Sophos4.47.02009.11.06-
Sunbelt3.2.1858.22009.11.06-
Symantec1.4.4.122009.11.06-
TheHacker6.5.0.2.0622009.11.05-
TrendMicro9.0.0.10032009.11.06-
VBA323.12.10.112009.11.06-
ViRobot2009.11.6.20252009.11.06-
VirusBuster4.6.5.02009.11.06-


File
Obama visit Asia.pdf
MD533aa28b079b33c1609f9096ee78e73c8
Analysis Started2009-11-06 12:10:45
Report Generated2009-11-06 12:10:53
Jsand version1.03.02

Detection results

DetectorResult
Jsand 1.03.02malicious

Exploits

NameDescriptionReference
Adobe Collab overflowMultiple Adobe Reader and Acrobat buffer overflowsCVE-2007-5659
Adobe getIconStack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab objectCVE-2009-0927

 

 

 










Monday, November 2, 2009

Win32/Opachki.A - Trojan that removes Zeus (but it is not benign)

Links updated: Jan 18, 2023

Download. Email me if you need the password
1) 
6762a2e15913e66b06a0953387bd87b0f9ce22b5939fe1efd46c7120df214d7c
2) 
MD5 00f2fd5e2c125965c188754f04da576c
SHA-1 63d53f6e1b3f9fb23c88b19f7c6326da45753a5d
SHA-256 a602a3dd91b5aa0e0e68d20efe787e01c9548cb1b11b5032541c2e7d4edb5710



Win32/Opachki.A --Virustotal-all antivirus names for it. The real tragedy is in those  http://www.threatexpert.com/report.aspx?md5=87a2583de6f6fbb5104e0433e89b1bcf


nsrbgxod.bak created by Opachki http://www.threatexpert.com/report.aspx?md5=87a2583de6f6fbb5104e0433e89b1bcf and nsrbgxod.bak created by Zeus/ZBot http://www.threatexpert.com/report.aspx?md5=00f2fd5e2c125965c188754f04da576c (link lost)



Different hash


SecureWorks Opachki Trojan Analysis http://www.secureworks.com/research/threats/opachki

Threatexpert

Submission details:

Filename(s)

1 %Temp%\nsrbgxod.bak

0 bytes


MD5: D41D8CD98F00B204E9800998ECF8427E
SHA-1: DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
2 %UserProfile%\protect.dll
%Programs%Startup\ChkDisk.dll
%System%\autochk.dll


[file and pathname of the sample #1]


24,064 bytes

MD5: 0x87A2583DE6F6FBB5104E0433E89B1BCF

SHA-1: 6048D36DB2207A1CEA877742C9403A816D711C6D

Mal/UnkPack-Fam
[Sophos]

TrojanDropper:Win32/Opachki.A

[Microsoft]

Trojan-Dropper.Win32.Opachki

[Ikarus]

3 %Programs%\Startup\ChkDisk.lnk



655 bytes



MD5: 0x6F61156F14AEED438770D31391E67EC9

SHA-1: 0x277B806CEC1AEDE9F9B934B7DD655D0BBB542597

Read more -  Update March 2010 

New banking trojan W32.Silon -msjet51.dll

Links updated: Jan 18, 2023

Friday, October 30, 2009

Oct-29 PDF attack. PART II -- North Korea - from georgeyork@mail.house.gov - 204.174.223.60 Thu, 29 Oct 2009 08:41:03 -

Links updated: Jan 18, 2023


Download. Email me if you need the password
Dear Colleague,
Attached is the report on North Korea. Please let me know if you have any interest in this.
Regards,
George York
House Committee on Ways & Means
2170 Rayburn House Office Building
Tel: (202) 225-5021
Fax: (202) 225-2035

Avast 4.8.1351.0 2009.10.29 PDF:Dropper-E
BitDefender 7.2 2009.10.30 Trojan.SWF.HeapSpray.B
DrWeb 5.0.0.12182 2009.10.30 Exploit.PDF.332
F-Secure 9.0.15370.0 2009.10.30 Trojan.SWF.HeapSpray.B
GData 19 2009.10.30 Trojan.SWF.HeapSpray.B
Microsoft 1.5202 2009.10.30 Exploit:Win32/Pidief.X
Additional information
File size: 417217 bytes
MD5...: 56f0aee46d36bb43bed513172e39a38e
SHA1..: 7cd8aaa246ce9e117827178a12ab0169f762fa0d
SHA256: 37ac149b6dc8b377d481b8d5b3147039b2aecbfe834f300a97f8de14c2ae115b
ssdeep: 768:MkcWFYRkrEPz7OAFzqJBEWcCm+BwQroYPu1PDjHE/rec+8N7zJv9lJtdRx7s
sJpV:lcWM/3UBEFq8ieLjkJ+Ov9ldR/OcX

Oct 29 CVE-2009-1862 North Korea - from Spoofed georgeyork@mail.house.gov - 204.174.223.60 Thu, 29 Oct 2009 08:41:03 -

Links updated: Jan 18, 2023


Download 56F0AEE46D36BB43BED513172E39A38E-North Korea.zip (password protected archive, please contact me if you need the pasword)

 


 

From: York, George [mailto:georgeyork@mail.house.gov]
Sent: Thursday, October 29, 2009 9:41 AM
To: Undisclosed-Recipient:;
Subject: North Korea

Dear Colleague,
 
Attached is the report on North Korea.  Please let me know if you have any interest in this.
 
Regards,
 
George York 
House Committee on Ways & Means
2170 Rayburn House Office Building
Tel:  (202) 225-5021
Fax: (202) 225-2035
Update of December 16, 2009 - file rescan
https://www.virustotal.com/gui/file/37ac149b6dc8b377d481b8d5b3147039b2aecbfe834f300a97f8de14c2ae115b
Antivirus Version Last Update Result
Avast 4.8.1351.0 2009.12.17 PDF:Dropper-E
BitDefender 7.2 2009.12.17 Trojan.SWF.HeapSpray.B
ClamAV 0.94.1 2009.12.17 Exploit.PDF-708
Comodo 3268 2009.12.17 UnclassifiedMalware
DrWeb 5.0.0.12182 2009.12.17 Exploit.PDF.332
F-Secure 9.0.15370.0 2009.12.16 Trojan.SWF.HeapSpray.B
GData 19 2009.12.17 Trojan.SWF.HeapSpray.B
Kaspersky 7.0.0.125 2009.12.17 Exploit.SWF.Agent.ci
McAfee 5834 2009.12.16 Exploit-PDF.z
McAfee+Artemis 5834 2009.12.16 Exploit-PDF.z
Microsoft 1.5302 2009.12.16 Exploit:Win32/Pidief.X

PCTools 7.0.3.5 2009.12.17 Trojan.Generic
Sunbelt 3.2.1858.2 2009.12.17 Exploit.PDF-JS.Gen (v)

Oct.29 PDF attack. NYT op ed by NAJIM ABED AL-JABOURI from expert-wgs@usip.org - Thu, 29 Oct 2009 08:41:03

The message sender was expert-wgs@usip.org ambdavidmack@yahoo.com The message originating IP was 64.18.0.20 The message recipients were ouruser@ourdomain.org The message was titled NYT op ed by NAJIM ABED AL-JABOURI The message date was Thu, 29 Oct 2009 10:48:47 -0700 The message identifier was <717097.91003.qm@web45801.mail.sp1.yahoo.com> The virus or unauthorised code identified in the email is: >>> Possible MalWare 'JS/Selfaltering.TxSp' found in >>> '5964260_2X_PM2_EMQ_MH__message.htm'. Heuristics score: 321

Compromised computer

C:\RECYCLER\1\nc\exe. And in the black screen that pops up it reads: mail.linkum.com.br [216.75.20.82] 8082 (?) open
Hostname:
mail.linkum.com.br
ISP:
California Regional Intranet
Organization:
California Regional Intranet
Proxy:
None detected
Type:
Corporate
Blacklist:
Geo-Location Information
Country:
United States
State/Region:
ME
City:
Prospect Harbor
Latitude:
44.4286
Longitude:
-68.0052
Area Code:
207

Thursday, October 15, 2009

Oct. 15, 2009 Attack of the Day. Trojan.Swifi /Trojan.SWF.HeapSpray.B / Exploit:Win32/Pidief.S 中共二炮部隊導彈之發展 The Development of Communist China's Second Artillery Corps Missile from F560123@ms13.hinet.net Thu 10/15/2009 10:50 PM


Links updated: Jan 18, 2023
Download infected pdf 新型導彈技術發展.pdf (Password protected archive. Please contact me if you need the password)


From: CHaiwang [mailto:F560123@ms13.hinet.net]
Sent: Thursday, October 15, 2009 10:50 PM
To:
Subject: 中共二炮部隊導彈之發展

請參閱附件!!!!

中共解放軍研究所
蔡萬助
2009/10/16

注意: 若要保護電腦對抗病毒,電子郵件程式可以防止傳送或接收特定類型的檔案附件。請檢查您的電子郵件安全性設定來確定附件如何處理


    machine translation (pls contribute a better one, thank you)

 From: CHaiwang [mailto: F560123@ms13.hinet.net]
    
Sent: Thursday, October 15, 2009 10:50 PM
    
To:
    
Subject:
    
Please refer to Annex!!!!
    
Chinese People's Liberation Army Institute of ?

        2009/10/16
    Note: To protect your computer against viruses, e-mail program can prevent sending or receiving certain types of file attachments. Please check your e-mail security settings to determine how to handle attachments

Virustotal results
https://www.virustotal.com/gui/file/e13fa200c0b2ac9c9f2c722b261ca881a7bee277014ca6e85cff5db3941d6643
File ________________________.pdf received on 2009.12.18 03:47:11 (UTC)
Result: 18/41 (43.90%)
 Compact Print results  Antivirus Version Last Update Result
a-squared 4.5.0.43 2009.12.18 Exploit.Win32.Pidief!IK
AntiVir 7.9.1.114 2009.12.17 EXP/Pidief.ban
Antiy-AVL 2.0.3.7 2009.12.17 Exploit/Win32.Pidief
Authentium 5.2.0.5 2009.12.02 PDF/Expl.CG
Avast 4.8.1351.0 2009.12.18 PDF:Dropper-D
BitDefender 7.2 2009.12.18 Trojan.SWF.HeapSpray.B
ClamAV 0.94.1 2009.12.18 Exploit.PDF-247
Comodo 3279 2009.12.18 UnclassifiedMalware
eSafe 7.0.17.0 2009.12.16 Win32.Swifi
F-Secure 9.0.15370.0 2009.12.17 Exploit:W32/Pidief.JC
GData 19 2009.12.18 Trojan.SWF.HeapSpray.B
Ikarus T3.1.1.79.0 2009.12.18 Exploit.Win32.Pidief
Kaspersky 7.0.0.125 2009.12.18 Exploit.Win32.Pidief.crd
McAfee-GW-Edition 6.8.5 2009.12.18 Exploit.Pidief.ban
Microsoft 1.5302 2009.12.18 Exploit:Win32/Pidief.S
Panda 10.0.2.2 2009.12.15 Exploit/Pdfka
PCTools 7.0.3.5 2009.12.18 Trojan.Swifi
Symantec 1.4.4.12 2009.12.18 Trojan.Swifi 


Tuesday, October 13, 2009

Oct.13 PDF attack Taiwan op-ed - from imbsecurty@gmail.com Tue, 13 Oct 2009 22:08:02 +0800 -

The message sender was
imbsecurty@gmail.com
The message originating IP was 209.85.216.187 The message recipients were
ouruser@ourdomain.org

The message was titled Taiwan op-ed
The message date was Tue, 13 Oct 2009 22:08:02 +0800 The message identifier was

 <d3fe9be60910130708u204cb8bo4ee320dc72621dfd@mail.gmail.com>
The virus or unauthorised code identified in the email is:

Possible MalWare 'Exploit/Zordle.gen' found in '5832758_3X_PM5_EMS_MA-PDF__Taiwan=20op=2Ded.pdf'. Heuristics score: 201
Possible MalWare 'Exploit/SWF.Noppy.gen' found in '5832758_3X_PM5_EMS_MA-PDF__Taiwan=20op=Ded.pdf::pdf_extract_0'. Heuristics score: 200
Possible MalWare 'Exploit/SWF.Noppy.gen' found in '5832758_3X_PM5_EMS_MA-PDF__Taiwan=20op=Ded.pdf::pdf_extract_1'. Heuristics score: 200





Friday, October 2, 2009

Oct. 2 PDF attack of the day. Fwd: U.S. Assiatance to North Korea from mark.manyin@gmail.com Fri, 2 Oct 2009 22:22:06

Links updated: Jan 18, 2023

Download 028ebdeea729a8c18ca1406ff102088d U.S. Assiatance to North Korea.pdf (Password protected archive. Please contact me if you need the password)

From: Mark Manyin [mailto:mark.manyin@gmail.com]
Sent: Friday, October 02, 2009 10:22 AM
Subject: Fwd: U.S. Assiatance to North Korea

Dear Colleagues,

I was able to secure permission to forward you the attached report on U.S. Assiatance to North Korea. We intentionally kept it short report, in hopes that it would increase its readership.

Please share with your colleagues. Also, please share their comments, observations and questions.

Best,

Mark Manyin
Specialist in Asian Affairs
Congressional Research Service
7-7653


The message sender was
    mark.manyin@gmail.com

The message originating IP was 209.85.222.117 The message recipients were
xxx@xxx.xxx

The message was titled Fwd: U.S. Assiatance to North Korea The message date was Fri, 2 Oct 2009 22:22:06 +0800 The message identifier was <1aa371b60910020722l10e85dd1v7b8fb8b4f05514bc@mail.gmail.com>
The virus or unauthorised code identified in the email is:
F-Secure Security Platform version 1.12  build 6412 Copyright (c) 1999-2007 F-Secure Corporation. All Rights Reserved.

Scan started at Fri Oct  2 14:40:46 2009 Database version: 2009-10-02_07

attach/5965436_3X_PM5_EMS_MA-PDF__U.S.=20Assiatance=20to=20North=20Korea.pdf: Infected: Exploit.Win32.Pidief.bvw [AVP]

Scan ended at Fri Oct  2 14:40:46 2009
2 files scanned
1 file infected


Monday, September 28, 2009

Sept 28. Attack of the Day. Exploit/MSWordAgent!IK Townhall Magazine... from spoofed xxxx@heritage.org

Link updated: Jan 18, 2023

Download Final File of F4 UN.doc (password protected archive. Please contact me if you need the password)

Update January 24, 2010  Abhishek Lyall provided the following information about the file:
" The exploit works on office 2003. Tested on XP SP2-3. The exe is embedded at OFFSET=0x4c00 with key 0x25. The Word document attached is at offset 0x7400 with key 0x25. The shellcode in the exploit drops a binary with name "svchost.exe" and a doc file in %temp% folder. The shellcode in the xls decodes the exe and drops it. The binary and Doc are XOR'ed with key 0x25 except bytes 0x25, 0x00, 0xFF and 0xDA". to be continued.. 




Virustotal
https://www.virustotal.com/gui/file/36b8f38a18856e5d5484ee5ef933706cb8372047470c63d6017d638448716dac

File Final File of F4 UN.doc received on 2009.10.22 18:31:54 (UTC)
Result: 4/41 (9.76%)
Antivirus     Version     Last Update     Result
a-squared     4.5.0.41     2009.10.22     Exploit.MSWord.Agent!IK
Antiy-AVL     2.0.3.7     2009.10.22     Exploit/MSWord.Agent
Ikarus     T3.1.1.72.0     2009.10.22     Exploit.MSWord.Agent
Kaspersky     7.0.0.125     2009.10.22  Exploit.MSWord.Agent.ac
File size: 1440768 bytes
MD5   : 76af62049aa95ba30214cabb5baf1342
SHA1  : 0ddff5948e3bf612eecbe7fc5bdd746939eb50c5
SHA256: 36b8f38a18856e5d5484ee5ef933706cb8372047470c63d6017d638448716dac


I don't know why a-squared stopped detecting it. One month later detection is still very low.

https://www.virustotal.com/gui/file/36b8f38a18856e5d5484ee5ef933706cb8372047470c63d6017d638448716dac
File Final_File_of_F4_UN.doc received on 2009.12.21 05:45:17 (UTC)
Result: 3/41 (7.32%)
Antiy-AVL    2.0.3.7    2009.12.18    Exploit/MSWord.Agent
Authentium    5.2.0.5    2009.12.02    MSWord/Dropper.B!Camelot
Kaspersky    7.0.0.125    2009.12.21 Exploit.MSWord.Agent.ac
Additional information
File size: 1440768 bytes
MD5...: 76af62049aa95ba30214cabb5baf1342
SHA1..: 0ddff5948e3bf612eecbe7fc5bdd746939eb50c5
SHA256: 36b8f38a18856e5d5484ee5ef933706cb8372047470c63d6017d638448716dac

to be continued..

Monday, September 21, 2009

Sep 21, 2009 CVE-2009-3957 PDF w Trojan Scar - 2009 Defense Seminar Invitation from randinfodesk@gmail.com Sep 21, 2009

Link updated: Jan 18, 2023

Download the files below as a password protected archive (please contact me if you need the password)


Original
E42F8E662D39A31B596D86504B9DC287 RandInfo.pdf  104165 bytes

Embedded / Dropped Files
590a6e6c811e41505bebd4a976b9e7f3 msapt.exe 41472 bytes
590a6e6c811e41505bebd4a976b9e7f3 update.exe 41472 bytes  230040293ED381E32FAA081B76634FCB wshipa.dll 32768 bytes 74180904D2F9DF2553C478F7AC480527 tpdefense.dat 103 bytes E73C3121EE1ED30643E1D1982393F978 RANDInfo.pdf 37822 bytes
Details E42F8E662D39A31B596D86504B9DC287 RandInfo.pdf


From: RAND Corporation [mailto:randinfodesk@gmail.com]
Sent: Monday, September 21, 2009 8:04 AM
Subject: 2009 Defense Seminar Invitation

       
RAND  Defense Security Seminar

October 19-23, 2009
1200 South Hayes Street
Arlington, VA 22202-5050

RAND Coporation will hold 2009 Defense Seminar at RAND’s Washington office at Pentagon City, Arlington, VA. Sessions will be held from 9:00 to 5:00 with an hour lunch break on Monday through Thursday, October 19–22, and from 9:00 to 1:00 on Friday, October 23, 2009.

Topics covered will include the following:
- The evolution of alliance and coalition partnerships
- The major issues and challenges in East Asia
- Gaming techniques for strategists and planners
- Missile defense technology and policy
- Transforming intelligence agencies to be better prepared to deal with today's threats
For more information, you can see attached file.
  
______________________________
Contact:
RAND Corporation
1200 South Hayes Street
Arlington, VA 22202
Phone: 703/412-1100 x5409
Fax: 703/413-8181


Tuesday, June 2, 2009

win32update.exe MD5 eec80fd4c7fc5cf5522f0ca4eb2d9c6f

Link updated: Jan 18, 2023

https://www.virustotal.com/gui/file/4f6e68bff29aed584a68c21616dd8c052ba0eee220c911d98b9bb9fabe7db06a


File win32update.exe received on 2009.06.02 04:43:06 (UTC)
Result: 15/39 (38.47%)
Located in c:\windows\system32
Prevx
3
2009.06.02
Medium Risk
NOD32
4121
2009.06.02
probably Win32/PSW.Agent
AVG
8.5.0.339
2009.06.01
PSW.Agent.XOU
AntiVir
7.9.0.180
2009.06.01
TR/PSW.Agent.kny
BitDefender
7.2
2009.06.02
Trojan.Generic.980251
GData
19
2009.06.02
Trojan.Generic.980251
McAfee-GW-Edition
6.7.6
2009.05.29
Trojan.PSW.Agent.kny
VirusBuster
4.6.5.0
2009.06.01
Trojan.PWS.Agent.HWJL
TheHacker
6.3.4.3.335
2009.06.01
Trojan/PSW.Agent.kny
CAT-QuickHeal
10
2009.06.01
TrojanPSW.Agent.kny
F-Secure
8.0.14470.0
2009.06.02
Trojan-PSW.Win32.Agent.kny
Kaspersky
7.0.0.125
2009.06.02
Trojan-PSW.Win32.Agent.kny
VBA32
3.12.10.6
2009.06.02
Trojan-PSW.Win32.Agent.kny
Authentium
5.1.2.4
2009.06.02
W32/Pws.BIXJ
F-Prot
4.4.4.56
2009.06.02
W32/Pws.BIXJ