Clicky

Pages

Tuesday, December 22, 2009

Dec. 22 Attack of the Day Trojan.SWF.HeapSpray.B 2010 Congressional, Political and Holiday Schedule from Council for a Livable World from jdsaacs@clw.org




Download infected schedule 2010.pdf (password protected archive. Please contact me if you need the password) - 4875fc26b1507b0f70770253c1bfd3a9



 From: John Isaacs [mailto:jdsaacs@clw.org]
Sent: Tuesday, December 22, 2009 3:37 AM
To: "Undisclosed-Recipient:;"
Subject: 2010 Congressional, Political and Holiday Schedule from Council for a Livable World


    2010 Congressional, Political, Cultural and Holiday Schedule
    Items highlighted in yellow related to Congress
   

    January

    Friday, Jan. 1: New Year’s Day (federal holiday)
    Tuesday, Jan. 5 - Second session of Congress reconvenes in a pro forma session
    Thursday, Jan. 7: BCS college football championship game - Alabama vs. Texas
    Tuesday, Jan. 12: House reconvenes for legislative business
    Monday, Jan. 18: Martin Luther King, Jr. Day (federal holiday)
    Tuesday, Jan. 19: Senate reconvenes for legislative business
    Tuesday, Jan. 19: Mass. special Senate election - Martha Coakley (D) vs. Scott Brown (R)
    Late Jan.:  President Obama’s State of the Union address
    February



Dec. 22. Adobe 0 Day. Attack of the Day. 報告書(排出権取引に関する記述) from XXXREDACTED@mofa.go.jp Tue, 22 Dec 2009 09:36:20 +0800


Update Dec 22 7:40 am: Several new variants of  CVE-2009-4324 arrived since yesterday in different targeted messages. I do not have time to post them now but hope to do it, eventually. I think the trickle of messages containing this type of exploit now turned into a shower and is likely to become a downpour. I hope the AV vendors and Adobe are working hard on their detection and fixes because the current VT results are a bit worrisome.


--------------------------------------

Somehow I doubt that the Ministry of Foreign Affairs of Japan http://www.mofa.go.jp/ joined the the zero day games, however, the headers seem to point to their network or someone using it.--- never mind, they don't. "mofa.go.jp 117.11.119.251" is not really mofa.go.jp (Updated Dec.22 7:30 am).


Update. Dec 22 15:30
The spoofed message is crafted to look like a message from an existing high ranking official in the Ministry of Foreign Affairs of Japan . Contents of the message and pdf are in Japanese and are pieces of documents discussing emissions controls. The documents contained names of various officials and full correct contact information of the alleged sender from MOFA. Since I do not speak Japanese, I had to seek advice from people who can read Japanese and make such decisions. I have been told that while they are obviously fakes, it would take too much time and effort to make sure the documents contain no sensitive information and therefore the message contents should not be released. I cannot publish them after receiving the recommendations above, there will be no samples on this one (M)


The message sender was

XXXREDACTED@mofa.go.jp
The message originating IP was 117.11.119.251 The message recipients were
XXX@XXX.XXX
The message was titled 報告書(排出権取引に関する記述)
The message date was Tue, 22 Dec 2009 09:36:20 +0800 The message identifier was (empty) The virus or unauthorised code identified in the email is:
>>> Possible MalWare 'Exploit/Acroread-CVE-2009-4324' found in
>>> '7913605_1000X_PA2_APDF__pdf_obj_42_0.js'. Heuristics score: 251


Dec 22 Exploit/Zordle.gen Attack of the Day US China Statement from spoofed sender Tue, 22 Dec 2009 22:26:45



Download infected US China Statement.pdf (Password protected archive, please contact me if you need the password) 




The message sender was
    Spoofed
 message recipients were
    XXX@XXX.XXX
The message was titled US China Statement.
The message date was Tue, 22 Dec 2009 22:26:45 +0800 The message identifier was <08db01ca8312$f3b7a7f0$9301a8c0@testacb8580da5>
The virus or unauthorised code identified in the email is:
>>> Possible MalWare 'Exploit/Zordle.gen' found in
>>> '5964330_4X_PM6_EMS_MA-OCTET=2DSTREAM__US=20China=20Statement.pdf'.
>>> Heuristics score: 201



Monday, December 21, 2009

Dec. 21 Adobe 0 Day CVE-2009-4324 PDF Attack of the Day SEF preparatory discussions list 陸委會轉寄 海基會、海協會協商代表團預備性磋商名單 from macnews@mac.gov.tw Mon, 21 Dec 2009 20:37:15 +0800


Download infected pdf 海基會協商代表團預備性磋商名單.pdf as SEFdiscussionsm.zip. Password protected, please use the same as on other CVE-2009-4324 files or contact me for the password

Yawn.  Here is one more. 



From: macnews [mailto:macnews@mac.gov.tw]
Sent: Monday, December 21, 2009 7:37 AM
To: XXXXXXXXXXXX
Subject: 陸委會轉寄 海基會、海協會協商代表團預備性磋商名單

您好,附件為本次協商海基會、海協會代表團預備性磋商名單,提供給您參考,謝謝。

__________ Information from ESET NOD32 Antivirus, version of virus signature database 4707 (20091221) __________The message was checked by ESET NOD32 Antivirus.
http://www.eset.com
Here is a terrible machine translation but it is easy to understand that the mailing is fueled by the recent news, namely, the talks between the ARATS  (Association for Relations Across the Taiwan Straits) and SEF (Straits Exchange Foundation)  in Taichung tomorrow, December 22, 2009.


From: macnews [mailto: macnews@mac.gov.tw]
Sent: Monday, December 21, 2009 7:37 AM
To: XXXXXXXXXXXX
Subject: MAC forwarding SEF and ARATS consultations, the delegation of the list of preliminary consultations
Hello, see attached third Consultative SEF and ARATS delegation of the list of preliminary consultations provided for your reference, thank you. 



Nov 30 -- Dec 21 CVE-2009-4324 Summary of posts with samples




Download all files together with the binary downloaded from hxxxp://foruminspace.com/documents/dprk/ (Password protected archive. Use the same password you used on the samples above or contact me for the password)

  1. See post with CVE-2009-4324 Sample#0 (Nov. 30, 2009)  note200911.pdf 61baabd6fc12e01ff73ceacc07c84f9a
  2. See post with CVE-2009-4324 sample #1 (Dec 11, 2009) note_20091210.pdf  61baabd6fc12e01ff73ceacc07c84f9a
  3. See post with CVE-2009-4324 sample #2 (Dec. 13, 2009) Outline of Interview.pdf 35e8eeee2b94cbe87e3d3f843ec857f6
  4. See post with CVE-2009-4324 Sample #3 (Dec 18, 2009) merry christmas.pdf  955bade419a9ba9e5650ccb3dda88844
  5. See post with CVE-2009-4324 Sample #4 (Dec 18, 2009) 「寶貝悶」瘋狂照.pdf --renamed to crazyphoto.zip 8950bbedf4a7f1d518e859f9800f9347  
  6. See post with CVE-2009-4324 Sample #5 (Dec 21, 2009) 海基會協商代表團預備性磋商名單.pdf renamed to SEFdiscussionsm.zip.0ab2fd3b6c385049f9eb4a559dbdc8a6 ---New





Dec 21 Attack of the Day.Exploit/Zordle.gen Information on the forum invitation from Yenfei.Su@gmail.com Tue, 22 Dec 2009 11:08:24 +0800


Download infected pdf as ForumInvitation.zip (Password protected, please contact me if you need it)


The message sender was
Yenfei.Su@gmail.com
The message originating IP was 168.95.4.116 The message recipients were
XXX@XXX.XXX
The message was titled 座談會邀請資料
The message date was Tue, 22 Dec 2009 11:08:24 +0800 The message identifier was
The virus or unauthorised code identified in the email is:
>>> Possible MalWare 'Exploit/Zordle.gen' found in
>>> '5963899_4X_PM5_EMS_MA-OCTET=2DSTREAM__=A5=C9=A4s=B1M=C3D3=AD=D7.pdf
>>> '. Heuristics score: 201


Headers
 Received: from msr32.hinet.net (HELO msr32.hinet.net) (168.95.4.132)
  by XXXXXX SMTP; 22 Dec 2009 03:07:58 -0000
Received: from IBM-62979760B13 (61-218-117-75.HINET-IP.hinet.net [61.218.117.75])
    by msr32.hinet.net (8.9.3/8.9.3) with ESMTP id LAA19335
    for XXXXXXXX: Yenfei.Su@gmail.com
From: "Yen-fei Su"
To: XXXXXXXXXXX
Subject: =?BIG5?B?rnm9zbd8wdy90LjqrsY=?=
Date: Tue, 22 Dec 2009 11:07:38 +0800
Message-Id:
MIME-Version: 1.0
Content-Type: multipart/mixed;     boundary="----=_NextPart_09122211024143786257804_000"
X-Priority: 3
X-Mailer: DreamMail 4.5.0.0Received: (qmail 8043 invoked from network); 22 Dec 2009 03:07:58 -0000




Saturday, December 19, 2009

[2009-12-19] Analysis of CVE-2009-4324 samples by extraexploit

Please see analysis of CVE-2009-4324 samples kindly provided by extraexploit.

Samples from Dec 18 



Adobe CVE-2009-4324 in the wild - (0day) - part 0.3 - merry christmas

Samples from Nov.30, Dec 11, and Dec 13
Adobe CVE-2009-4324 in the wild - (0day) - part 0.2 - shellcode and site down
Adobe CVE-2009-4324 in the wild - (0day) - part 0.1 - browsing C&Cs
Adobe CVE-2009-4324 in the wild - (0day) - part 0



Dec 18 Adobe 0 day CVE-2009-4324 PDF attack of the Day (#5) merry christmas from uyghurhunova@yahoo.com Fri, 18 Dec 2009 11:11:27 -0800



 Download infected merry_christmas.pdf (password protected, please contact me or use the same password as you used on other CVE-2009-4324 samples)


Adobe is taking their sweet time to fix the problem while new variants show up. You don't need  ESP to predict that Christmas cards will be followed by New Year's invites and IRS forms before most people receive and install the updates. I was surprised that Symantec, being the CVE-2009-4324 pack leader in the past few days, did not detect it.  Tip of the hat to Messagelabs for catching it again.





From: Uyghur Hunova uyghurhunova@yahoo.com
Subject: merry christmas
Sent: Fri 12/18/2009 2:09 PM
My dear friend
Merry Christmas


 The message sender was
 uyghurhunova@yahoo.com
The message originating IP was 98.137.27.222 The message recipients were
    XXX@XXX.XXX
The message was titled merry christmas
The message date was Fri, 18 Dec 2009 11:11:27 -0800 (PST) The message identifier was <474701.46814.qm@web112506.mail.gq1.yahoo.com>
The virus or unauthorised code identified in the email is:
>>> Possible MalWare 'Exploit/Acroread-CVE-2009-4324' found in
>>> '8044614_1000X_PA3_APDF__pdf_obj_31_0.js'. Heuristics score: 401

Friday, December 18, 2009

Dec 18 Adobe 0 day CVE-2009-4324 PDF attack of the Day (#4) 女兵脫衣比中指 拍照PO上網 from gpwbinfo@mna.gpwb.gov.tw Sat, 19 Dec 2009 10:22:01 +0800

 



This message is targeted but not perfect - not all recipients of that message can read Chinese. I posted the machine translation in the end of the post, it is about some alleged recent strip photo scandal in the People's Liberation Army.

This message shows that detection of the new threat remains tricky. Messagelabs apparently used Symantec scanners to stop and tag the threat yet Symantec did not detect it when it was scanned on Virustotal. Not to mention a distressingly low overall detection rate -  7 out of 41.

The message sender was
    gpwbinfo@mna.gpwb.gov.tw
The message originating IP was 203.252.1.122 The message recipients were
    XXX@XXX.XXX
The message was titled 女兵脫衣比中指 拍照PO上網
The message date was Sat, 19 Dec 2009 10:22:01 +0800 The message identifier was  1975e5623c$23fce32a$0ae1d8b4@gpwbinfo212af2ce2>
The virus or unauthorised code identified in the email is:
Trojan.Pidief.H -- Symantec definitiions :)




From: 軍聞社 [mailto:gpwbinfo@mna.gpwb.gov.tw]
Sent: Friday, December 18, 2009 9:22 PM
To: XXXXXXXXX
Subject: 女兵脫衣比中指 拍照PO上網

        網路上流傳一組名為「寶貝悶」的國軍女兵脫衣照,因行徑大膽前所未見,隨即引起轟動;原本外界以為是假照片,後來經查,撩衣照片主角竟是現任聯勤司令部中部運輸大隊一中隊行政士的陳學葳女中士。照片曝光後,陳學葳向軍方坦承,這是去年二月後勤學校受訓結束時,與同學慶祝的「瘋狂照」。 ...
 (See the full text in the end of the post.)
 .....
__________ Information from ESET NOD32 Antivirus, version of virus signature database 4700 (20091218) __________
The message was checked by ESET NOD32 Antivirus.
http://www.eset.com    -


Virustotal
http://www.virustotal.com/analisis/55227b229a113d8a93d823466ebdd7a94c77fa37126b330818b41d49bd9a73de-1261202919
File ________________________.pdf received on 2009.12.19 06:08:39 (UTC)
Result: 7/41 (17.08%)
BitDefender    7.2    2009.12.19    Exploit.PDF-JS.Gen
F-Secure    9.0.15370.0    2009.12.19    Exploit.PDF-JS.Gen
GData    19    2009.12.19    Exploit.PDF-JS.Gen
Kaspersky    7.0.0.125    2009.12.19    Exploit.Win32.Pidief.cxi
McAfee-GW-Edition    6.8.5    2009.12.18    Heuristic.BehavesLike.PDF.Suspicious.Z
PCTools    7.0.3.5    2009.12.19    Trojan.Pidief
Symantec    1.4.4.12    2009.12.18 --Ok, Symantec, what happened here?
Sunbelt    3.2.1858.2    2009.12.19    Exploit.PDF-JS.Gen (v)

Additional information
File size: 51822 bytes
MD5...: 8950bbedf4a7f1d518e859f9800f9347
SHA1..: e4d30ecbe13765c4448e0b140db2569c58aa39f8
SHA256:
55227b229a113d8a93d823466ebdd7a94c77fa37126b330818b41d49bd9a73dessdeep: 768:bsg8fN3eX7k3GHsF90azVWqaYXCqntyhovHhv/MVsMepOF:bTYN3z3Uscazp
XM25EZepG


Wepawet Analysis
http://wepawet.cs.ucsb.edu/view.php?hash=8950bbedf4a7f1d518e859f9800f9347&type=jsAnalysis report for 「寶�悶�瘋狂照.pdf
File 「寶�悶�瘋狂照.pdf
MD5 8950bbedf4a7f1d518e859f9800f9347
Analysis Started 2009-12-18 20:10:54
Report Generated 2009-12-18 20:10:58
Jsand 1.03.02 malicious
doc.media.newPlayer Use-after-free vulnerability in the Doc.media.newPlayer method in Adobe Reader and Acrobat 8.0 through 9.2 CVE-2009-4324


Tuesday, December 15, 2009

Dec.13-Dec.11-Nov.30 Adobe CVE-2009-4324 posts with infected samples.



Download all together with the binary that it downloads from hxxxp://foruminspace.com/documents/dprk/ (Password protected archive. Use the same password you used on the samples above or contact me for the password)

Note: A few people reported problems with unzipping the files - use 7Zip http://www.7-zip.org if you do. Please email the name of the file or provide a link when asking for a password.

See post with CVE-2009-4324 Sample#0 (Nov. 30, 2009)  note200911.pdf 61baabd6fc12e01ff73ceacc07c84f9a
See post with CVE-2009-4324 sample #1 (Dec 11, 2009) note_20091210.pdf  61baabd6fc12e01ff73ceacc07c84f9a
See post with CVE-2009-4324 sample #2 (Dec. 13, 2009) Outline of Interview.pdf 35e8eeee2b94cbe87e3d3f843ec857f6



Nov.30 Adobe 0 day CVE-2009-4324 PDF attack of the Day (#0) This is the very first we received. FW: reference from chrisanderson58@hotmail.com Mon, 30 Nov 2009 06:56:23


This message shows that Adobe zero day exploit has been in the wild and actively exploited by attackers since at least November 30, 2009 not December 11 or 14, 2009  Note the name of the file note200911.pdf is slightly different from Dec. 11, 2009 note_20091210.pdf  but it is the same MD5 61baabd6fc12e01ff73ceacc07c84f9a


From: Chris Anderson [mailto:chrisanderson58@hotmail.com]
Sent: 2009-11-30 1:56 AM
To: XXX@XXX.XXX
Subject: FW: reference
________________________________________
From: jackr@gilbrooks.edu
To: chrisanderson58@hotmail.com
Subject: reference
Date: Mon, 30 Nov 2009 06:53:52 +0000


Dear All
Please find attached the updated country briefing notes, and staff lists.


Kind regards
Jack



Virustotal
results of Dec. 15 2009
File note200911.pdf received on 2009.12.15 16:20:58 (UTC)
http://www.virustotal.com/analisis/27cced58a0fcbb0bbe3894f74d3014611039fefdf3bd2b0ba7ad85b18194cffa-1260894058
Result: 13/41 (31.71%)

a-squared 4.5.0.43 2009.12.15 Exploit.JS.Pdfka!IK
AhnLab-V3 5.0.0.2 2009.12.15 PDF/CVE-2009-4324
AntiVir 7.9.1.108 2009.12.15 HTML/Malicious.PDF.Gen
Comodo 3254 2009.12.15 UnclassifiedMalware
eSafe 7.0.17.0 2009.12.15 PDF.Exploit.4
F-Secure 9.0.15370.0 2009.12.15 Exploit:W32/AdobeReader.UZ
Ikarus T3.1.1.74.0 2009.12.15 Exploit.JS.Pdfka
Kaspersky 7.0.0.125 2009.12.15 Exploit.JS.Pdfka.atq
McAfee-GW-Edition 6.8.5 2009.12.15 Script.Malicious.PDF.Gen
Microsoft 1.5302 2009.12.15 Exploit:Win32/Pdfjsc.CO
NOD32 4690 2009.12.15 PDF/Exploit.Gen
PCTools 7.0.3.5 2009.12.15 Trojan.Pidief
Symantec 1.4.4.12 2009.12.15 Trojan.Pidief.H

File size: 400918 bytes
MD5...: 61baabd6fc12e01ff73ceacc07c84f9a
SHA1..: 0805d0ae62f5358b9a3f4c1868d552f5c3561b17
SHA256: 27cced58a0fcbb0bbe3894f74d3014611039fefdf3bd2b0ba7ad85b18194cffa
ssdeep: 1536:p0AAH2KthGBjcdBj8VETeePxsT65ZZ3pdx/ves/aQR/875+:prahGV6Bj8V


Messagelabs was catching it on November 30, 2009.

The message sender was
chrisanderson58@hotmail.com
 

The message was titled FW: reference
The message date was Mon, 30 Nov 2009 06:56:23 +0000 The message identifier was
The virus or unauthorised code identified in the email is:
Possible MalWare 'JS/PDFEncoded' found in
5963825_1001X_PA4_APDF__pdf_obj_110_0.js'. Heuristics score: 650



See post with CVE-2009-4324 sample #2
See post with CVE-2009-4324 sample #1

Dec.13 Adobe 0 day CVE-2009-4324 PDF attack of the Day (#2) Interview Request from fureer.angelica@gmail.com Sun, 13 Dec 2009 14:13:46


Download "Outline of interview" infected pdf. (password protected archive. Contact me for the password. If you got the first verison of the adobe zero day of Fri, Dec 11, the password is the same) 
Note: A few people reported problems with unzipping the files - use 7Zip http://www.7-zip.org if you do. Please email the name of the file or provide a link when asking for a password.

New Adobe zero day exploit message (#2)  See #1 here
From: Fureer Angelica [mailto:fureer.angelica@gmail.com]
Sent: 2009-12-13 12:14 AM
To: XXXXXX
Subject: Interview Request


This is Fureer Angelica, diplomaic broadcaster for CNN in DC.
There's growing concern about the U.S.-North Korea bilateral talks.
So, we're planning an Interview about them.
Attached is the outline of the interview.


p.s. Detailed schedules will be followed soon if you accept the offer.

Messagelabs detects it easily
The message sender was
fureer.angelica@gmail.com

The message originating IP was 209.85.222.117 The message recipients were
XXX@XXX.XXX

The message was titled Interview Request The message date was Sun, 13 Dec 2009 14:13:46 +0900 The message identifier was <9c3b16360912122113s2a953d1dqfdb5a6ddb8f35c5a@mail.gmail.com>
The virus or unauthorised code identified in the email is:
Possible MalWare 'JS/PDFEncoded' found in
'5963838_1001X_PA3_APDF__pdf_obj_110_0.js'. Heuristics score: 651


Adobe 0-day analysis by F-secure

F-Secure folks (thanks mikkohypponen) released their analysis of Adobe 0 day - as mentioned in the post by Extraexploit, it attempts to download ab.exe from hxxxp://foruminspace.com/documents/dprk/ab.exe

Adobe zero day quick analysis by Extraexploit

UPDATE
More technical details from extraexploit http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild.html


As this updated post of December 11, 2009 shows, a new Adobe zero day vulnerability is currently in the wild. If you are a malware analyst, grab your copy in the post and contact me for the infected pdf archive password.

Extraexploit analyzed his sample and reports that it drops ab.exe (download it from his blog or here and email for the pass). Apparently, ab.exe generates traffic to 124.217.238.101

Virustotal analysis of ab.exe 686738eb5bb8027c524303751117e8a9
File ab.exe received on 2009.12.15 12:38:33 (UTC)
Result: 8/40 (20%)
Antivirus Version Last Update Result
AntiVir 7.9.1.108 2009.12.15 TR/Drop.Agent.DT
Avast 4.8.1351.0 2009.12.15 Win32:Rootkit-DC
GData 19 2009.12.15 Win32:Rootkit-DC
McAfee+Artemis 5832 2009.12.14 Artemis!686738EB5BB8
Panda 10.0.2.2 2009.12.14 Suspicious file
PCTools 7.0.3.5 2009.12.15 Trojan.Dropper
Sophos 4.48.0 2009.12.15 Mal/Behav-027
Symantec 1.4.4.12 2009.12.15 Trojan.Dropper
Additional information
File size: 386016 bytes
MD5...: 686738eb5bb8027c524303751117e8a9
SHA1..: ad2ebe58b0ae2322b3ca6590f617c5a8ecc7b411
SHA256: d6afb2a2e7f2afe6ca150c1fade0ea87d9b18a8e77edd7784986df55a93db985
ssdeep: 6144:53Gcbn2gnsuwtasAlbkdIiXb8K/hYcZVnHIbNwJBBp5:JbwtasAV+xffZ5X

Threatexpert report on 686738eb5bb8027c524303751117e8a9

Sunbelt analysis of 686738eb5bb8027c524303751117e8a9


Monday, December 14, 2009

Dec.14 Attack of the Day. Hu Jintao Unveils Major Foreign-Policy Initiative from wilam@jamestown.org / jse96458@gmail.com Mon, 14 Dec 2009 08:51:24

Download infected PDF cb_009_70.pdf (Password protected archive, You need to contact me for the password)

Details - cb88aa793cbf180138673289f49342b7  cb_009_70.pdf 



From: Willy Lam [mailto:wilam@jamestown.org]
Sent: 2009-12-14 8:51 AM
To: Undisclosed-Recipient:;
Subject: Hu Jintao Unveils Major Foreign-Policy Initiative


Dear Colleagues,


Chinese President Hu Jintao has signaled his administration's readiness to play a bigger—and perhaps more constructive—role in global affairs through the release of a five-pronged foreign policy game plan. Cited by the official Outlook Weekly as “Hu Jintao’s Viewpoints about the Times,” this far-reaching initiative consists of five theories on, respectively, “the profound changes [in the world situation], constructing a harmonious world, joint development, shared responsibilities, and enthusiastic participation [in global affairs].”


In a late November issue of Outlook Weekly (a mouthpiece of the Chinese Communist Party [CCP]), ideologue Zhang Xiaotong indicated that the party chief and president’s “viewpoints” amounted to a “major theoretical innovation” based on the “scientific judgment of the development and changes of the times.” This ambitious agenda has been unveiled after U.S. President Barack Obama’s visit to China and before the Copenhagen climate change summit, two events that could become milestones in the Middle Kingdom’s quest for quasi-superpower status.


Thought some of you might be interested in attached paper on China's foreign policy.


If you have any questions, let me know.


Regards,


Willy
--
Willy Lam
Senior Fellow, China Program
The Jamestown Foundation
Virustotal results

File cb_009_70.pdf received on 2009.12.14 17:05:25 (UTC)
Result: 6/41 (14.64%)

BitDefender 7.2 2009.12.14 Exploit.PDF-JS.Gen
F-Secure 9.0.15370.0 2009.12.14 Exploit.PDF-JS.Gen
GData 19 2009.12.14 Exploit.PDF-JS.Gen
Kaspersky 7.0.0.125 2009.12.14 Exploit.JS.Pdfka.ara
NOD32 4686 2009.12.14 PDF/Exploit.Gen
Sophos 4.48.0 2009.12.14 Troj/PDFJs-FM
Additional information


Friday, December 11, 2009

Dec.11 Adobe 0 day CVE-2009-4324 Attack of the Day (#1). Fwd: Reference from christanderson.ma@gmail.com Fri 2009-12-11 01:08


Download infected pdf. (password protected archive. Please contact me for the password)

The message sender was
chrisanderson.ma@gmail.com

The message originating IP was 209.85.223.197 The message recipients were
XXX@XXX.XXX

The message was titled Fwd: reference
The message date was Fri, 11 Dec 2009 15:18:05 +0900 The message identifier was <3b0a7fee0912102218y2a5125b6l647440877727e6cc@mail.gmail.com>
The virus or unauthorised code identified in the email is:
Possible MalWare 'JS/PDFEncoded' found in'5963958_1001X_PA3_APDF__pdf_obj_110_0.js'. Heuristics score: 651




From: Rachel Millstone
Date: Dec 11, 2009 3:12 PM
Subject: reference
To: chrisanderson.ma@gmail.com

Dear All
Please find attached the updated country briefing notes, and staff lists.

Kind regards
Rachel



Virustotal
File note_20091210.pdf received on 2009.12.11 17:35:39 (UTC)
Result: 4/41 (9.76%)

AntiVir 7.9.1.108 2009.12.11 HTML/Malicious.PDF.Gen
eSafe 7.0.17.0 2009.12.10 PDF.Exploit.4
McAfee-GW-Edition 6.8.5 2009.12.11 Script.Malicious.PDF.Gen 
NOD32 4679 2009.12.11 PDF/Exploit.Gen 

Update (December14-2009)
Virustotal
received on 2009.12.15 05:16:00 (UTC)
Result: 8/41 (19.52%)
http://www.virustotal.com/analisis/27cced58a0fcbb0bbe3894f74d3014611039fefdf3bd2b0ba7ad85b18194cffa-1260854160
AntiVir 7.9.1.108 2009.12.14 HTML/Malicious.PDF.Gen
Comodo 3248 2009.12.15 UnclassifiedMalware
eSafe 7.0.17.0 2009.12.14 PDF.Exploit.4
Kaspersky 7.0.0.125 2009.12.15 Exploit.JS.Pdfka.atq
McAfee-GW-Edition 6.8.5 2009.12.15 Script.Malicious.PDF.Gen
NOD32 4688 2009.12.15 PDF/Exploit.Gen
PCTools 7.0.3.5 2009.12.15 Trojan.Pidief
Symantec 1.4.4.12 2009.12.15
Trojan.Pidief.H

Adobe 0 - day  CVE-2009-4324
http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html
http://www.symantec.com/connect/blogs/zero-day-xmas-present





Thursday, December 10, 2009

Dec.12 Creative NSA and Pentagon spoof. Infected with Packed.Generic.271 or Zeus? CYBER-PMESII COMMANDER’S ANALYSIS OF FORECAST EFFECTS from ecu@nsa.gov or jh.colving@js.pentagon.mil Wed, 9 Dec 2009 07:49:06 and 09:25:41

The links appear to be dead at this point. Infected with Packed.Generic.271 (Zeus?)
AFRL-RI-RS-TR-2009-136
Final Technical Report
December 2009

CYBER-PMESII COMMANDER’S ANALYSIS OF FORECAST EFFECTS (CYBERCAFE)

INFORMATION SUBJECT TO EXPORT CONTROL LAWS

WARNING - This document contains technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C., Sec 2751 et seq.) or the Export Administration Act of 1979, as amended (Title 50, U.S.C. App. 2401, et seq.). Violations of these export laws are subject to severe criminal penalties. Disseminate IAW DoDD 5230.25.

DESTRUCTION NOTICE - For classified documents, follow the procedures in DOD 5220.22-M, National Industrial Security Manual (NISPOM), section 5-705 or DOD 5200.1-R, Information Security Program, Chapter VI. For unclassified limited documents, destroy by any method that will prevent disclosure of contents or reconstruction of the document.

Export of the attached information (which includes, in some circumstances, release to foreign nationals within the United States) without first obtaining approval or license from the Department of State for items controlled by the International Traffic in Arms Regulation (ITAR), or the Department of Commerce for items controlled by the Export Administration Regulation (EAR), may constitute a violation of law.

Download:
http://www.zeropaid.com/bbs/includes/CYBERCAFE.zip

or

http://rapidshare.com/files/318309046/CYBERCAFE.zip.html
http://www.sendspace.com/file/fmbt01


Monday, December 7, 2009

Dec.7 Attack of the Day. Poison Ivy zip download link. Our soliders in Afghanistan Mon. Dec 07, 2009 10:34 AM




Download Afghanistan.zip 052e62513505a25ccfadf900a052709c http://www.mediafire.com/file/dwo2kih2ayn/Afghanistan8.zip



 From: XXX@yahoo.com]
Sent: Monday, December 07, 2009 10:34 AM
To: XXX@xxx.xxx
Subject: Our soliders in Afghanistan
President Obama recently announced that he was determined to "finish the job"
in Afghanistan, and aides signaled to allies that he would send as many as
25,000 to 30,000 additional American troops there. 2009 is shaping up to be
the deadliest year yet for coalition troops - twice as deadly as 2008.
Here are images of the country and conflict over the past month...
http://www.dreamlifes.net/Afghanistan/Afghanistan.zip
Regards


Virustotal scan 
http://www.virustotal.com/analisis/16952bc60a64af478fd7fd74bfb662b2f2c26cebc515cf4d17adeed90da6cf06-1260935214
File Afghanistan.scr received on 2009.12.16 03:46:54 (UTC)
Result: 22/41 (53.66%)

a-squared 4.5.0.43 2009.12.16 Riskware.RemoteAdmin.Win32.PoisonIvy!IK
AhnLab-V3 5.0.0.2 2009.12.15 Dropper/Malware.1259008.B
AntiVir 7.9.1.108 2009.12.15 TR/Mepaow.jvr
Avast 4.8.1351.0 2009.12.15 Win32:Malware-gen
AVG 8.5.0.427 2009.12.15 SHeur2.BTHV.dropper
BitDefender 7.2 2009.12.16 BehavesLike:Win32.ExplorerHijack
eSafe 7.0.17.0 2009.12.15 Win32.TRMepaow.Jvr
F-Secure 9.0.15370.0 2009.12.15 BehavesLike:Win32.ExplorerHijack
Fortinet 4.0.14.0 2009.12.16 RAT/PoisonIvy
GData 19 2009.12.16 BehavesLike:Win32.ExplorerHijack
Ikarus T3.1.1.77.0 2009.12.16 not-a-virus:RemoteAdmin.Win32.PoisonIvy
K7AntiVirus 7.10.920 2009.12.14 not-a-virus:RemoteAdmin.Win32.PoisonIvy.c
Kaspersky 7.0.0.125 2009.12.16 not-a-virus:RemoteAdmin.Win32.PoisonIvy.c
McAfee+Artemis 5833 2009.12.15 potentially unwanted program Artemis!052E62513505
McAfee-GW-Edition 6.8.5 2009.12.15 Trojan.Mepaow.jvr
nProtect 2009.1.8.0 2009.12.15 Trojan/W32.Agent.1259008.C
Panda 10.0.2.2 2009.12.15 Malicious Packer
PCTools 7.0.3.5 2009.12.16 Backdoor.Trojan
Rising 22.26.02.01 2009.12.16 Backdoor.Win32.RemoteAdmin.a
Sophos 4.48.0 2009.12.16 Mal/Generic-A
Sunbelt 3.2.1858.2 2009.12.16 Trojan.Win32.Generic!BT
Symantec 1.4.4.12 2009.12.16 Backdoor.Trojan

Additional information
File size: 1259008 bytes
MD5...: 052e62513505a25ccfadf900a052709c
SHA1..: 5ba291b3a0810bc319e243bb496f3b99a5280a64
SHA256: 16952bc60a64af478fd7fd74bfb662b2f2c26cebc515cf4d17adeed90da6cf06
ssdeep: 24576:PxW/6gOd4NpwO7ghtSaKvq+dh1j9gBYH+/kXEok48:ZWlhwWghtSq+rjgB

Headers
....
Received: from [174.139.22.106] by web56506.mail.re3.yahoo.com via HTTP; Mon, 07 Dec 2009 07:33:57 PST

X-Mailer: YahooMailClassic/8.1.6 YahooMailWebService/0.8.100.260964
Date: Mon, 7 Dec 2009 07:33:57 -0800 (PST)
From: XXXXXXXXX stolen yahoo account
Subject: Our soliders in Afghanistan
To: XXXXXXXX
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-743893425-1260200037=:86552"
Return-Path: XXXXXXXXX stolen yahoo account
X-OriginalArrivalTime: 07 Dec 2009 15:34:01.0709 (UTC) FILETIME=[B39069D0:01CA7752]

174.139.22.106
Hostname: customer.krypt.com

ISP: VPLS Inc. d/b/a Krypt Technologies
Organization: Kevin Perry
Type: Corporate
Country: United States
State/Region: CO
City: Boulder

Sunday, December 6, 2009

Dec.6 PDF attack. What Can the U.S. Learn from China’s Energy Policy? from matthewgebert@yahoo.com Sun, 6 Dec 2009 06:56:40


Download infected attachments (password protected archive. You will have to contact me for a password)




From: Matthew Gebert [mailto:matthewgebert@yahoo.com]


Sent: Sunday, December 06, 2009 9:57 AM


To: matthewgebert@yahoo.com


Subject: What Can the U.S. Learn from China’s Energy Policy?






The joke among China hands goes like this: If the Americans and the Chinese start talking about a major project today, in two years the Chinese will be done and the Americans will still be talking and applying for permits.
The message sender was
    matthewgebert@yahoo.com

 The message was titled What Can the U.S. Learn from China’s Energy Policy?
The message date was Sun, 6 Dec 2009 06:56:40 -0800 (PST) The message identifier was <133325.58274.qm@web113916.mail.gq1.yahoo.com>
The virus or unauthorised code identified in the email is:
F-Secure Security Platform version 1.12  build 6412 Copyright (c) 1999-2007 F-Secure Corporation. All Rights Reserved.

Scan started at Sun Dec  6 14:56:44 2009 Database version: 2009-12-05_02

attach/5963824_3X_PM5_EMS_MA-PDF__China=27s=2DEnergy=2DPolicy=2DAnalysis.pdf: Infected: Exploit.SWF.Agent.ci [AVP]
attach/5963824_4X_PM6_EMS_MA-PDF__WhatCantheU.S.LearnfromChina=27sEnergyPolicy.pdf: Infected: Exploit.JS.Pdfka.ajt [AVP]

Scan ended at Sun Dec  6 14:56:45 2009
5 files scanned
2 files infected



Wednesday, December 2, 2009

Dec.2 PDF attack. Re-Remarks of President Barack Obama from damien.tomkins@gmail.com Wed, 2 Dec 2009 22:22:04


Download the infected pdf (password protected archive, you have to contact me for the password)


The message sender was
damien.tomkins@gmail.com

The message originating IP was 209.85.222.112 The message recipients were
   ouruser@ourdomain.xxx

The message was titled Re-Remarks of President Barack Obama The message date was Wed, 2 Dec 2009 22:22:04 +0800 The message identifier was
The virus or unauthorised code identified in the email is:
F-Secure Security Platform version 1.12  build 6412 Copyright (c) 1999-2007 F-Secure Corporation. All Rights Reserved.

Scan started at Wed Dec  2 14:23:01 2009 Database version: 2009-12-02_15

attach/7815385_4X_AR_PA3__Remarks=20of=20President=20Barack=20Obama.pdf: Infected: Exploit.JS.Pdfka.amp [AVP]

Scan ended at Wed Dec  2 14:23:01 2009
3 files scanned
1 file infected




Tuesday, December 1, 2009

Dec.1 PDF Attack of the day. Russian-Proposed European Security Treaty from sullivanchris81@yahoo.com Tue, 1 Dec 2009 04:30:47


The message sender was
sullivanchris81@yahoo.com

The message originating IP was 98.136.165.26 The message recipients were
XXX@XXX.XXX

The message was titled Russian-Proposed European Security Treaty The message date was Tue, 1 Dec 2009 04:30:47 -0800 (PST) The message identifier was <729208.94960.qm@web112801.mail.gq1.yahoo.com>
The virus or unauthorised code identified in the email is:
F-Secure Security Platform version 1.12 build 6412 Copyright (c) 1999-2007 F-Secure Corporation. All Rights Reserved.

Scan started at Tue Dec 1 12:30:52 2009 Database version: 2009-12-01_03

attach/5964623_3X_PM5_EMS_MA-PDF__European=20Security=20Treaty=2D1.pdf: Infected: Exploit.JS.Pdfka.ara [AVP]
attach/5964623_4X_PM6_EMS_MA-PDF__European=20Security=20Treaty=2D2.pdf: Infected: Exploit.JS.Pdfka.ara [AVP]

Scan ended at Tue Dec 1 12:30:52 2009
3 files scanned
2 files infected

Dear Colleagues,

Just in case you have not seen this, I attached the draft treaty for your infomation. The treaty was posted on the website of the Russian Government.

Hope it will be help for your work.

Regards,

Chris