This is a good overview of the current PDF malware (up to September 2010)
Download paper
This appendix has a very nice chart of what is what when it comes to PDF these days (Click to enlarge)
Thursday, September 16, 2010
Sep 15 CVE-2010-2883 Adobe 0-Day PDF US Government Programs to Pay Medical Expenses from rodney.cadataa@gmail.com
CVE-2010-2883 Security Advisory for Adobe Reader and Acrobat
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
Download Beneficial medical programs.pdf and dropped files as a password protected archive (contact me if you need the password)
From: CENTERS FOR MEDICARE & MEDICAID SERVICES [mailto:rodney.cadataa@gmail.com]
Sent: Wednesday, September 15, 2010 10:22 AM
To: XXXXXXXXXXXXXXXXXX
Subject: US Government Programs to Pay Medical Expenses
There are Federal and state programs available for people with Medicare who have limited income and resources. These programs may help you save on your health care and prescription drug costs.
For More Information
Call or visit your State Medical Assistance (Medicaid) office, and ask for information on Medicaid and Medicare Savings Programs. The names of these programs and how they work may vary by state. Call if you think you qualify for any of these programs, even if you aren't sure.
Call 1-800-MEDICARE (1-800-633-4227), and say "medicaid" to get the telephone number for your state. TTY users should call 1-877-486-2048.
Sep14 CVE-2010-2883 Adobe 0-Day Fwd: China-U.S. Trade Issues from sara.ml.davis@gmail.com
CVE-2010-2883 Security Advisory for Adobe Reader and Acrobat
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
Download RL33536.pdf and dropped files as a password protected archive (contact me if you need the password)
1. Adobe PSIRT team confirmed that the attached exploit pdf is indeed for CVE-2010-2883 vulnerability and that their next update on October 4 will protect from a pdf like this one.
2. The message is from a gmail account but it is crafted to appear like a forwarded message by a CRS researcher. The real report with the researcher's name is published online and this is where they probably got the information.
(thanks to @xanda for sending the link to the report)
3. The pdf appears to be generated with Metasploit. (thanks to villy for the clue)
From: Davis L.M. [mailto:sara.ml.davis@gmail.com]
Sent: Tuesday, September 14, 2010 10:11 AM
To: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Subject: Fwd: China-U.S. Trade Issues
---------- Forwarded message ----------
From: Wayne M. Morrison
Date: 2010/9/14
Subject: China-U.S. Trade Issues
To: sara.ml.davis@gmail.com
FYI.
Wayne M. Morrison
Congressional Research Service
Specialist in Asian Trade and Finance
Sep 16 CVE-2010-2883 PDF INTEREST & FOREIGN EXCHANGE RATES
Download INTEREST_&_FOREIGN_EXCHANGE_RATES.pdf and dropped files as a password protected archive (contact me if you need the password)
-----Original Message-----
From: XXXXXXXXXXXXXXXXXXXXXXXXXXXXSent: Thursday, September 16, 2010 11:32 AMTo: XXXXXXXXXXXXXXSubject: INTEREST & FOREIGN EXCHANGE RATESDear XXXXXXXXXXXXXXXXXXX,Hope this email finds you well.Maby you are intersted of this article.Apologies for this sudden request, but we would greatly appreciate your advice.Best Regards,----------------------------------------------------------------This message was sent using IMP, the Internet Messaging Program.
Thursday, September 9, 2010
Sep 09 CVE-2009-4324 + CVE-2010-1297 + CVE-2009-0927 PDF U.S. economy slips from spoofed henryAron@brookings.org 210.64.253.96
Download as a password protected archive with the original PDf and analysis files/dropped binaries (contact me if you need the password)
-----Original Message-----
From: Henry J. Aaron [mailto:henryAron@brookings.org]
Sent: Thursday, September 09, 2010 9:38 AM
To: XXXXXXXXX
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To whom it may concern.
Henry J. Aaron
Senior Fellow, Economic Studies
The Brookings Institution
Headers
Received: (qmail 12137 invoked from network); 9 Sep 2010 13:43:33 -0000
Received: from h96-210-64-253.seed.net.tw (HELO brookings.org) (210.64.253.96)
by XXXXXXXXXXXX with SMTP; 9 Sep 2010 13:43:33 -0000
From: "Henry J. Aaron"
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To: XXXXXXX
Content-Type: multipart/mixed;
boundary="=_NextPart_2rfkindysadvnqw3nerasdf"; charset="US-ASCII"
MIME-Version: 1.0
Reply-To: h.swain65@yahoo.com
Date: Thu, 9 Sep 2010 21:37:54 +0800
X-Priority: 3
X-Mailer: Microsoft Outlook Express 5.00.2615.200
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To: XXXXXXX
Content-Type: multipart/mixed;
boundary="=_NextPart_2rfkindysadvnqw3nerasdf"; charset="US-ASCII"
MIME-Version: 1.0
Reply-To: h.swain65@yahoo.com
Date: Thu, 9 Sep 2010 21:37:54 +0800
X-Priority: 3
X-Mailer: Microsoft Outlook Express 5.00.2615.200
210.64.253.96
ISP: Digital United Inc.
Organization: Seednet-TaipeiDP-S
State/Region: T'ai-pei
City: Taipei
CVE-2009-4324
CVE-2010-1297
CVE-2009-0927
http://wepawet.cs.ucsb.edu/view.php?hash=47a46ba2220cf6368eb0d42d8a6d40e3&type=js
Saturday, September 4, 2010
Defcon 18 Audio in MP3 files
Defcon 18 MP3 files
TRACK 1
- Track-1_Perspectives_in_Cybersecurity_and_Cyberwarfare_Max_Kelly
- Track 1 Meet the Feds - CSITCPIP Panel
- Track 1 DNS Systemic Vulnerabilities and Risk Management A Discussion Panel
- Track 1 Meet the Feds - Policy, Privacy, Deterrence and Cyber War Panel
- Track 1 Enough Cyber Talk Already! Help Get this Collaboration Engine Running Riley Repko
- Track 1 Open Letter - Call to Action Panel
- Track 1 Of Bytes and Bullets Panel
- Track 1 Exploiting WebSphere Application Server’s JSP Engine Ed Schaller
- Track 1 Mastering the Nmap Scripting Engine Fyodor David Fifield
- Track 1 Meet the EFF Kevin Bankston- Eva Galperin- Jennifer Granick- Marcia Hofmann- Kurt Opsahl
- Track 1 Black Ops Of Fundamental Defense Web Edition Dan Kaminsky
- Track 1 Legal Developments in Hardware Hacking Jennifer Granick Matt Zimmerman
- Track 1 App Attack Surviving the Mobile Application Explosion Kevin Mahaffey John Hering
- Track 1 This is Not the Droid You’re Looking For Nicholas J. Percoco- Christian Papathanasiou
- Track 1 Practical Cellphone Spying Chris Paget
- Track 1 HD Voice - The Overdue Revolution Doug Mohney
- Track 1 These Aren’t the Permissions You’re Looking For Anthony Lineberry- David Luke Richardson- Tim Wyatt
- Track 1 Mobile Privacy Tor on the iPhone and Other Unusual Devices Marco Bonetti
- Track 1 Resilient Botnet Command and Control with Tor
- Track 1 Ripping Media Off Of the Wire HONEY
- Track 1 The Search for Perfect Handcuffs... and the Perfect Handcuff Key Deviant Ollam- Dave- Dr. Tran- Ray
- Track 1 Attack the Key, Own the Lock Schuyler Towne- datagram
- Track 1 PCI Compromising Controls and Compromising Security Jack Daniel Panel
- Track 1 How I Met Your Girlfriend Samy Kamkar
- Track 1 Decoding reCAPTCHA Chad Houck- Jason Lee
- Track 1 So Many Ways to Slap A Yo-Ho Xploiting Yoville and Facebook for Tom Stracener Strace- Sean Barnum- Chris Peterson
- Track 1 Social Networking Special Ops Extending Data Visualization Tools The Suggmeister
- Track 1 Getting Social with the Smart Grid Justin Morehouse Tony Flick
TRACK 2
- Track 2 An Examination of the Adequacy of the Laws Related to Cyber Warfare Dondi West
- Track 2 Balancing the Pwn Trade Deficit Val Smith- Colin Ames- Anthony Lai
- Track 2 Build Your Own Security Operations Center for Little or No Money
- Track 2 Cloud Computing, a Weapon of Mass Destruction David VideoMan- M. N.Bryan- Michael Anderson
- Track 2 Cyber CrimeWarCharting Dangerous Waters Iftach Ian Amit
- Track 2 Cyberterrorism and the Security of the National Drinking Water Infrastructure John McNabb
- Track 2 Drivesploit Circumventing Both Automated AND Manual Wayne Huang
- Track 2 Exploiting SCADA Systems Jeremy Brown
- Track 2 Hacking and Protecting Oracle Database Vault Esteban Martínez Fayó
- Track 2 Hacking Oracle From Web Apps
- Track 2 How Unique Is Your Browser Peter Eckersley
- Track 2 Industrial Cyber Security Wade Polk- Paul Malkewicz- J. Novak
- Track 2 Kim Jong-il and Me How to Build a Cyber Army to Defeat the U.S. Charlie Miller
- Track 2 Lord of the Bing Taking Back Search Engine Hacking Rob Ragan- Francis Brown
- Track 2 Multiplayer Metasploit Tag-Team Penetration and Information Gathering Ryan Linn
- Track 2 NoSQL, No Injection Wayne Huang, Kuon Ding
- Track 2 Passive DNS Hardening Robert Edmonds- Paul Vixie
- Track 2 Powershell...omfg David Kennedy ReL1K-, Josh Kelley
- Track 2 SCADA and ICS for Security Experts How to Avoid Cyberdouchery James Arlen
- Track 2 Seccubus - Analyzing Vulnerability Assessment Data the Easy Way Frank Breedijk
- Track 2 SHODAN for Penetration Testers Michael Schearer
- Track 2 Tales from the Crypto G. Mark Hardy
- Track 2 The Night The Lights Went Out In Vegas Demystifying The Night The Lights Went Out In Vegas Demystifying Barrett Weisshaar, Garret Picchioni
- Track 2 The Power of Chinese Security Anthony Lai-Jake Appelbaum- Jon Oberheide.
- Track 2 Token Kidnapping's Revenge Cesar Cerrudo
- Track 2 Toolsmithing an IDA Bridge, Case Study for Building a RE tool Adam Pridgen, Matt Wollenweber
- Track 2 Wardriving the Smart Grid Practical Approaches to Attacking Utilit Shawn Moyer- Nathan Keltner
- Track 2 You Spent All That Money and You Still Got Owned Joseph McCray
TRACK 3
- Track 3 0box Analyzer AfterDark Runtime Forensics for Automated Malware Analysis and Clustering Wayne Huang, Jeremy Chiu, Benson Wu
- Track 3 A New Approach to Forensic Methodology - !!BUSTED!! Case Studies David C. Smith, Samuel Petreski
- Track 3 Advanced Format String Attacks Paul Haas
- Track 3 An Observatory for the SSLiverse Peter Eckersley, Jesse Burns
- Track 3 Bad Memories Elie Bursztein, Baptiste Gourdin, Gustav Rydstedt, Dan Boneh
- Track 3 Big Brother on the Big Screen FactFiction Nicole Ozer, Kevin Bankston
- Track 3 Browser Based Defenses James Shewmaker
- Track 3 Changing Threats To Privacy From TIA to Google Moxie Marlinspike
- Track 3 Connection String Parameter Attacks Chema Alonso, José Palazón "Palako"
- Track 3 Constricting the Web Offensive Python for Web Hackers Nathan Hamiel, Marcin Wielgoszewski
- Track 3 Exploiting Internet Surveillance Systems Decius
- Track 3 FOCA2 The FOCA Strikes Back Chema Alonso, José Palazón "Palako"
- Track 3 Hacking DOCSIS For Fun and Profit Blake Self, bitemytaco
- Track 3 Hacking Facebook Privacy Chris Conley
- Track 3 How To Get Your FBI File (and Other Information You Want from the Federal Government) Marcia Hofmann
- Track 3 How to Hack Millions of Routers Craig Heffner
- Track 3 masSEXploitation Michael Brooks "The Rook"
- Track 3 Open Source Framework for Advanced Intrusion Detection Solutions Patrick Mullen, Ryan Pentney
- Track 3 Our Instrumented Lives Sensors, Sensors, Everywhere...Greg Conti
- Track 3 pyREtic - In-memory Reverse Engineering for Obfuscated Python Bytecode Rich Smith
- Track 3 Repelling the Wily Insider Matias Madou, Jacob West
- Track 3 Search & Seizure & Golfballs Jim Rennie, Eric Rachner
- Track 3 The Anatomy of Drug Testing Jimi Fiekert
- Track 3 The Law of Laptop Search and Seizure Jennifer Granick, Kevin Bankston, Marcia Hofmann, Kurt Opsahl
- Track 3 This Needs to be Fixed, and Other Jokes in Commit Statements Bruce Potter, Logan Lodge
- Track 3 WPA Too Md Sohail Ahmad
- Track 3 Your ISP and the Government Best Friends Forever Christopher Soghoian
TRACK 4
- track 4 Breaking Bluetooth by Being Bored JP Dunning
- track 4 Build a Lie Detector/Beat a Lie Detector Rain- urbanmonkey
- track 4 Build your own UAV 2.0 - Wireless Mayhem from the Heavens Michael Weigand- Renderman- Mike Kershaw
- track 4 Bypassing Smart-Card Authentication and Blocking Debiting Vulnerabilities in Atmel Cryptomemory-Based Stored-Value Systems Jonathan Lee- Neil Pahl
- track 4 DCFluX in: Moon-Bouncer Matt Krick
- track 4 Deceiving the Heavens to Cross the Sea Using the 36 Stratagems for Social Engineering Jayson E. Street
- track 4 Exploitation on ARM - Technique and Bypassing Defense Mechanisms Itzhak “zuk”” Avraham
- track 4 Exploiting Digital Cameras Oren Isacson- Alfredo Ortega
- track 4 ExploitSpotting: Locating Vulnerabilities Out of Vendor Patches Automatically Jeongwook Oh
- track 4 Extreme-Range RFID Tracking Chris Paget
- track 4 Function Hooking for Mac OSX and Linux Joe Damato
- track 4 Getting Root: Remote Viewing- Non-Local Consciousness Richard Thieme
- track 4 Hacking with Hardware: Introducing the Universal RF Usb Keboard Emulation Device - URFUKED Monta Elkins
- track 4 How Hackers Won the Zombie Apocalypse Dennis Brown
- track 4 Implementing IPv6 at ARIN Matt Ryanczak
- track 4 Insecurity Engineering of Physical Security Systems: Locks- Lies- and Videotape Marc Weber Tobias- Tobias Bluzmanis- Matt Fiddler
- track 4 IPv6: No Longer Optional John Curran
- track 4 Jackpotting Automated Teller Machines Redux Barnaby Jack
- track 4 Live Fire Exercise: Baltic Cyber Shield 2010 Kenneth Geers
- track 4 Physical Computing- Virtual Security: Adding the Arduino Microcontroller Leigh Honeywell- follower
- track 4 Physical Security Youre Doing It Wrong A.P. Delchi
- track 4 Programmable HID USB Keystroke Dongle Using the Teensy as a Pen Testing Device Adrian Crenshaw
- track 4 SMART Project: Applying Reliability Metrics to Security Vulnerabilities Blake Self- Wayne Zage- Dolores Zage
- track 4 VirGraff101: An Introduction to Virtual Graffiti Tottenkoph
- track 4 We Don’t Need No Stinkin Badges: Hacking Electronic Door Access Controllers Shawn Merdinger
- track 4 Weaponizing Lady GaGa- Psychosonic Attacks Brad Smith
- track 4 Web Services We Just Don’t Need Mike “mckt” Bailey
- track 4 Welcome and Making the DEF CON 18 Badge Dark Tangent- Joe Grand
TRACK 5
- Track 5 Air Traffic Control Insecurity 2.0 Righter Kunkel
- Track 5 Antique Exploitation aka Terminator 3.1.1 for Workgroups Jon Oberheide
- Track 5 Be a Mentor Marisa Fagan
- Track 5 Blitzableiter - the Release Felix FX Lindner
- Track 5 ChaosVPN for Playing CTFs mc.fly, ryd, vyrus, no_maam
- Track 5 Crawling BitTorrent DHTs for Fun Scott Wolchok
- Track 5 Defcon Security Jam III: Now in 3-D Panel
- Track 5 Electronic Weaponry or How to Rule the World While Shopping at Radio Shack Mage2
- Track 5 Evilgrade, You Still Have Pending Upgrades Francisco Amato- Federico Kirschbaum
- Track 5 Facial Recognition: Facts, Fiction; and Fcsk-Ups Joshua Marpet
- Track 5 FOE‚ The Release of Feed Over Email Sho Ho
- Track 5 From No Way to 0-day Weaponizing the Unweaponizable Joshua Wise
- Track 5 Gaming in the Glass Safe - Games DRM and Privacy Ferdinand Schober
- Track 5 Google Toolbar The NARC Within Jeff Bryner
- Track 5 Hacking .Net Applications A Dynamic Attack Jon McCoy
- Track 5 Hardware Hacking for Software Guys Dave King
- Track 5 Kartograph Finding a Needle in a Haystack or How to Apply Reverse Engineering Techniques to Cheat at Video Games Elie Bursztein Jocelyn Lagarenne
- Track 5 Katana Portable Multi-Boot Security Suite JP Dunning
- Track 5 Letting the Air Out of Tire Pressure Monitoring Systems Mike Metzger
- Track 5 Like a Boss: Attacking JBoss Tyler Krpata
- Track 5 Malware Freak Show 2 The Client-Side Boogaloo Nicholas J. Percoco, Jibran Ilyas
- Track 5 Malware Migrating to Gaming Consoles Embedded Devices an Antivirus-Free Safe Hideout For Malware Ahn Ki-Chan Ha Dong-Joo
- Track 5 My Life as a Spyware Developer Garry Pejski
- Track 5 oCTF: 5 years in 50 minutes Panel
- Track 5 Open Public Sensors and Trend Monitoring Daniel Burroughs
- Track 5 Operating System Fingerprinting for Virtual Machines Nguyen Anh Quynh
- Track 5 Pwned By The Owner What Happens When You Steal a Hacker’s Computer Zoz
- Track 5 Searching for Malware A Review of Attackers’ Use of Search Engines to Lure Victims David Maynor, Paul Judge, PhD
- Track 5 Securing MMOs A Security Professional’s View from the Inside metr0
- Track 5 The Games We Play Brandon Nesbit
- Track 5 Training the Next Generation of Hardware Hackers Andrew Kongs- Dr. Gerald Kane
- Track 5 Web Application Fingerprinting with Static Files Patrick Thomas
- Track 5 Who Cares About IPv6 Sam Bowne
- Track 5 WiMAX Hacking 2010 Pierce, Goldy, aSmig, sanitybit
- Track 5 Your Boss is a Douchebag... How About You Luiz effffn Eduardo
- DEFCON 18 Hacking Conference Presentation By Joe Grand and Dark Tangent - Welcome And Behind The Scenes Of The DEFCON Badge - Slides.m4v
- DEFCON 18 Hacking Conference Presentation By Barnaby Jack - Jackpotting Automated Teller Machines Redux - Slides.m4v
- DEFCON 18 Hacking Conference Presentation By David Maynor and Paul Judge - Searching For Malware - Slides.m4v
- DEFCON 18 Hacking Conference Presentation By Chris Paget - Practical Cellphone Spying - Slides.m4v
- DEFCON 18 Hacking Conference Presentation By Md Sohail Ahmad - WPA Too! - Slides.m4v
Many thanks to MG
Monday, August 30, 2010
APT IPs and Domains
From malware analysis, compromised systems, internet research and reader submissions
| Last Seen | IP (info link) | Country | Port | Source/Associated malware | MD5 | Domain/URL | Reverse | Contagio |
|---|---|---|---|---|---|---|---|---|
| 2010-Aug-19 2010-May-13 | 202.175.83.10 | Macau | 8000 443 | irmon32.dll ("Infrared Monitor" srvc) rasauto16.dll (Remote Access Auto Connection Manager srvc) | irmon32.dll 1966B265272E1660E6F340B19A7E5567 rasauto16.dll 15138604260b1d27f92bf1ec6468b326 | All are hardcoded in dll hxxp://sync.ns06.net/expirat/billing.htm | z83l10.static.ctm.net | Backdoor services |
2010-May-13 | 202.153.103.83 | Hong Kong | 443 | rasauto32.dll (Remote Access Auto Connection Manager srvc) | 995b44ef8460836d9091a8b361fde489 | beta.nethost.hk | Backdoor services | |
2010-Aug-19 | 64.184.2.11 | USA | 443 | sap.dll (SAP Agent srvc or NWSapagent) | 795B5E3E3D6C25B007498203A62693FA | |||
2010-Aug-19 | 63.134.215.218 | USA | 443 | sap.dll (SAP Agent srvc or NWSapagent) | F2A4B2F4A3EDFF07155C4F238240F40D | |||
| 2010-Aug-19 2010-May-13 | 202.175.83.10 | Macau | 8000 443 | irmon32.dll ("Infrared Monitor" srvc) rasauto16.dll (Remote Access Auto Connection Manager srvc) | irmon32.dll 1966B265272E1660E6F340B19A7E5567 rasauto16.dll 15138604260b1d27f92bf1ec6468b326 |
All are hardcoded in dll
hxxp://sync.ns06.net/expirat/billing.htm | z83l10.static.ctm.net | Backdoor services |
| 2010-Aug-24 | 211.234.11.125 72.167.62.13 | Republic of Korea GoDaddy, USA | 443 ? | irmon32.dll ("Infrared Monitor" srvc) | irmon32.dll E66DD357A6DFA6EBD15358E565E8F00F C75D351D86DE26718A3881F62FDDDE99 |
All are is hardcoded in dll:
navl.oTZO.com (aug30)
grey.qHigh.com (it .-aug31)
2010)-- 211.234.11.125
atures.gotdns.com (aug30)
ccoun.dnsalias.org (agu31)-- (72.167.62.13) | 211-234-111-125.kidc.net ip-72-167-62-13.ip. secureserver.net |
Mobile Malware Google Group. Mobile malware samples
Update January 21, 2011 - they exchange samples there and have active discussions. I do not post those samples here, join the group if you need them.
If you are interested in mobile malware analysis, join the Mobile Malware Group (Adam Russell is the moderator/founder and he is processing the requests)
If you are interested in mobile malware analysis, join the Mobile Malware Group (Adam Russell is the moderator/founder and he is processing the requests)
This group is intended as a service to the mobile malware research community as well as anyone interested in starting research in this growing field. As such, we are looking for discussions on various mobile systems such as the iPhone, Android, Symbian, and other mobile platforms. Discussions should target analysis of the malware, requests for samples of malware, technical reviews of new methods, and other related material and questions. My hope is that this community can grow and provide high quality, cogent information to new and veteran researchers alike. (- Adam Russell)
Description:
A mailing
list for researching mobile malware. This group allows material related to new
mobile malware samples, analysis, new techniques, questions pertaining to the
field, and other related material. Please describe yourself in short detail when
requesting to join. Thank you.
Saturday, August 28, 2010
Aug 27 SMS Send JAVA Mobile malware
I was planning to do something else tonight when my blackberry buzzed with a new message.Unfortunately, this was not the message I'd like to receive. ICQ spam is common and fairly predictable - invitations to new "cool chat rooms", offers to DDoS my competitors until they revert to using paper and pencil or spam every person on earth for pennies.This one offered a new 3D game called Little Tanks.
Download Tank_3d.jar 6fe6d19f61f2222421c2eda1f8c1dabe as a password protected archive (contact me if you need the password)
369506328 Теперь новые ТАНЧИКИ 3 Д на телефонах. Скачать можно по ссылке: http:/ /slil.ru/29608317/1326f51.4c78f7e8/Tank_3d.jar
* игра работает только на мобильных
369506328 Now new LITTLE TANKS 3D on phones. You can download it from this link http:/ /slil.ru/29608317/1326f51.4c78f7e8/Tank_3d.jar
* The game works only on mobile phones
Tank_3d\аларм наш
File name: Tank_3d.jar
http://www.virustotal.com/file-scan/report.html?id=bc06cf72c2b44f17808dff5b38373486346ea563220a6c7163e1e115f63f0040-1282962855
Submission date: 2010-08-28 02:34:15 (UTC)
Result: 17 /42 (40.5%)
AntiVir 8.2.4.46 2010.08.27 TR/SMS.J2ME.Smmer.f
Antiy-AVL 2.0.3.7 2010.08.26 Trojan/J2ME.Smmer
Avast 4.8.1351.0 2010.08.27 Other:Malware-gen
Avast5 5.0.594.0 2010.08.27 Other:Malware-gen
Comodo 5881 2010.08.28 UnclassifiedMalware
DrWeb 5.0.2.03300 2010.08.28 Java.SMSSend.185
Emsisoft 5.0.0.37 2010.08.27 Trojan-SMS!IK
F-Secure 9.0.15370.0 2010.08.28 Riskware:Java/SmsSend.Gen!A
GData 21 2010.08.28 Other:Malware-gen
Ikarus T3.1.1.88.0 2010.08.27 Trojan-SMS
Kaspersky 7.0.0.125 2010.08.28 Trojan-SMS.J2ME.Smmer.f
Microsoft 1.6103 2010.08.27 Trojan:Java/SMSer.I
NOD32 5403 2010.08.27 probably a variant of J2ME/TrojanSMS.Konov.L
PCTools 7.0.3.5 2010.08.28 Trojan.Gen
Symantec 20101.1.1.7 2010.08.28 Trojan.Gen
TrendMicro 9.120.0.1004 2010.08.27 TROJ_SMMER.B
TrendMicro-HouseCall 9.120.0.1004 2010.08.28 TROJ_SMMER.B
Additional informationShow all
MD5 : 6fe6d19f61f2222421c2eda1f8c1dabe
Download Tank_3d.jar 6fe6d19f61f2222421c2eda1f8c1dabe as a password protected archive (contact me if you need the password)
369506328 Теперь новые ТАНЧИКИ 3 Д на телефонах. Скачать можно по ссылке: http:/ /slil.ru/29608317/1326f51.4c78f7e8/Tank_3d.jar
* игра работает только на мобильных
369506328 Now new LITTLE TANKS 3D on phones. You can download it from this link http:/ /slil.ru/29608317/1326f51.4c78f7e8/Tank_3d.jar
* The game works only on mobile phones
Tank_3d\аларм наш
The file appears to be an sms sender like many. Donato Ferrante from InReverse analyzed a similar sample earlier this year.
http://www.virustotal.com/file-scan/report.html?id=bc06cf72c2b44f17808dff5b38373486346ea563220a6c7163e1e115f63f0040-1282962855
Submission date: 2010-08-28 02:34:15 (UTC)
Result: 17 /42 (40.5%)
AntiVir 8.2.4.46 2010.08.27 TR/SMS.J2ME.Smmer.f
Antiy-AVL 2.0.3.7 2010.08.26 Trojan/J2ME.Smmer
Avast 4.8.1351.0 2010.08.27 Other:Malware-gen
Avast5 5.0.594.0 2010.08.27 Other:Malware-gen
Comodo 5881 2010.08.28 UnclassifiedMalware
DrWeb 5.0.2.03300 2010.08.28 Java.SMSSend.185
Emsisoft 5.0.0.37 2010.08.27 Trojan-SMS!IK
F-Secure 9.0.15370.0 2010.08.28 Riskware:Java/SmsSend.Gen!A
GData 21 2010.08.28 Other:Malware-gen
Ikarus T3.1.1.88.0 2010.08.27 Trojan-SMS
Kaspersky 7.0.0.125 2010.08.28 Trojan-SMS.J2ME.Smmer.f
Microsoft 1.6103 2010.08.27 Trojan:Java/SMSer.I
NOD32 5403 2010.08.27 probably a variant of J2ME/TrojanSMS.Konov.L
PCTools 7.0.3.5 2010.08.28 Trojan.Gen
Symantec 20101.1.1.7 2010.08.28 Trojan.Gen
TrendMicro 9.120.0.1004 2010.08.27 TROJ_SMMER.B
TrendMicro-HouseCall 9.120.0.1004 2010.08.28 TROJ_SMMER.B
Additional informationShow all
MD5 : 6fe6d19f61f2222421c2eda1f8c1dabe
Friday, August 27, 2010
TDL3 dropper (x86 compatible with x64 systems)
Special thanks to kernelmode.info (and @GiuseppeBonfa "evilcry") for the sample.
Related research and news articles
- TDL3: The Rootkit of All Evil? * Account of an Investigation into a Cybercrime Group by Aleksandr Matrosov, senior virus researcher Eugene Rodionov, rootkit analyst
- Rootkit TDL 3 (alias TDSS, Alureon) from http://www.kernelmode.info/forum
- TDL3 rootkit x64 goes in the wild by Marco Giuliani
- Brief dynamic analysis of most recent TDL3 dropper screenshot Chae Jong Bin @2gg
- Tidserv 64-bit Goes Into Hiding - Symantec
- How to remove malware belonging to the family Rootkit.Win32.TDSS (aka Tidserv, TDSServ, Alureon)? - new
- send more, I will add
includes:
- custom_unpacked.zip
- MBR_TDL_Files.rar files dropped by the infection, his dropper, and an offline dump of the MBR.
- tdl3_dropper.zip
- Readme (please read)
TDL3 dropper compatible with x86 and x64 systems
File name: custom_exe
http://www.virustotal.com/file-scan/report.html?id=053c111b9e1be52256bb33e2622f71a2006ab06a6324fc80474dcb9e299e102e-1282910774
Submission date: 2010-08-27 12:06:14 (UTC)
Current status: finished
Result: 21 /40 (52.5%)
AhnLab-V3 2010.08.27.00 2010.08.26 Dropper/Win32.TDSS
AntiVir 8.2.4.46 2010.08.27 TR/Alureon.DX
Avast 4.8.1351.0 2010.08.27 Win32:Malware-gen
Avast5 5.0.594.0 2010.08.27 Win32:Malware-gen
AVG 9.0.0.851 2010.08.27 Generic18.BZWR
BitDefender 7.2 2010.08.27 Trojan.Generic.4657531
DrWeb 5.0.2.03300 2010.08.27 BackDoor.Tdss.4005
Emsisoft 5.0.0.37 2010.08.27 Trojan.Win32.Tdss!IK
F-Secure 9.0.15370.0 2010.08.27 Trojan.Generic.4657531
GData 21 2010.08.27 Trojan.Generic.4657531
Ikarus T3.1.1.88.0 2010.08.27 Trojan.Win32.Tdss
Jiangmin 13.0.900 2010.08.27 TrojanDropper.Agent.auzt
Kaspersky 7.0.0.125 2010.08.27 Trojan-Dropper.Win32.TDSS.fsa
McAfee 5.400.0.1158 2010.08.27 DNSChanger!eo
Microsoft 1.6103 2010.08.27 Trojan:Win32/Alureon.DX
NOD32 5401 2010.08.27 Win32/Olmarik.ADA
nProtect 2010-08-27.01 2010.08.27 Trojan-Dropper/W32.Agent.126464.Q
PCTools 7.0.3.5 2010.08.27 Backdoor.Tidserv
Prevx 3.0 2010.08.27 Medium Risk Malware
Symantec 20101.1.1.7 2010.08.27 Backdoor.Tidserv.L
TheHacker 6.5.2.1.356 2010.08.26 Trojan/Dropper.Agent.cuxr
Additional informationShow all
MD5 : 93c9658afb6519c2ca69edefbe4143a3
Virustotal Comments:
TDL3 dropper that is able to infect x86 and x64 systems. On x64 it uses a custom boot loader stored in the MBR that loads the kernel mode code without requiring a valid digital signature. Happy reversing :).
Thursday, August 26, 2010
Malicious Links August 2010
hXXp:// www.un.org/disarmament/convarms/ArmsTradeTreaty/html/ ATT-BackgroundDocuments. shtml
http://www.virustotal.com/file-scan/report.html?id=52398a10322e274da8065d81d40844a6da05134a097e31488c9dfda24c9f2d6d-1282854134
ATT-BackgroundDocuments.shtml
Submission date: 2010-08-26 20:22:14 (UTC)
Current status: finished
Result: 12 /41 (29.3%)
AVG 9.0.0.851 2010.08.25 JS/Downloader.Agent
ClamAV 0.96.2.0-git 2010.08.26 HTML.Crypt-5
DrWeb 5.0.2.03300 2010.08.26 VBS.Psyme.377
Emsisoft 5.0.0.37 2010.08.26 Trojan-Downloader.JS.Psyme!IK
F-Prot 4.6.1.107 2010.08.26 JS/Dccrypt.B.gen
Ikarus T3.1.1.88.0 2010.08.26 Trojan-Downloader.JS.Psyme
NOD32 5397 2010.08.25 JS/Agent.NCA
Panda 10.0.2.7 2010.08.25 JS/Agent.NRU
PCTools 7.0.3.5 2010.08.26 Trojan-Downloader.Inor!sd5
Sunbelt 6795 2010.08.26 Trojan-Downloader.JS.Inor.a (v)
VBA32 3.12.14.0 2010.08.25 Trojan-Downloader.JS.Agent.bx
VirusBuster 5.0.27.0 2010.08.25 JS.Wonka.Gen
Additional informationShow all
MD5 : 008e5df755dc0cadbaf009a84b587173
http://www.virustotal.com/file-scan/report.html?id=52398a10322e274da8065d81d40844a6da05134a097e31488c9dfda24c9f2d6d-1282854134
ATT-BackgroundDocuments.shtml
Submission date: 2010-08-26 20:22:14 (UTC)
Current status: finished
Result: 12 /41 (29.3%)
AVG 9.0.0.851 2010.08.25 JS/Downloader.Agent
ClamAV 0.96.2.0-git 2010.08.26 HTML.Crypt-5
DrWeb 5.0.2.03300 2010.08.26 VBS.Psyme.377
Emsisoft 5.0.0.37 2010.08.26 Trojan-Downloader.JS.Psyme!IK
F-Prot 4.6.1.107 2010.08.26 JS/Dccrypt.B.gen
Ikarus T3.1.1.88.0 2010.08.26 Trojan-Downloader.JS.Psyme
NOD32 5397 2010.08.25 JS/Agent.NCA
Panda 10.0.2.7 2010.08.25 JS/Agent.NRU
PCTools 7.0.3.5 2010.08.26 Trojan-Downloader.Inor!sd5
Sunbelt 6795 2010.08.26 Trojan-Downloader.JS.Inor.a (v)
VBA32 3.12.14.0 2010.08.25 Trojan-Downloader.JS.Agent.bx
VirusBuster 5.0.27.0 2010.08.25 JS.Wonka.Gen
Additional informationShow all
MD5 : 008e5df755dc0cadbaf009a84b587173
Aug 25 CVE-2010-1240 From Intelligence Fusion Centre with ZeuS trojan
Update: Please read detailed analysis of this and associated attacks
Crime or Espionage? by Nart Villeneuve
Intelligence Fusion Centre
In support of NATO
RAF Molesworth, United Kingdom
Unit 8845 Box 300, Huntingdon
CAMBS PE28 0QB
FROM: Intelligence Fusion Centre
SUBJECT: Military operation of the EU
Additional information can be found in the following report:
http:// gnarus.mobi/media/EuropeanUnion_MilitaryOperations_EN. zip
http:// quimeras.com.mx/media/EuropeanUnion_MilitaryOperations_EN.ip
> EUROPEAN UNION
> EUROPEAN SECURITY AND DEFENCE POLICY
> Military operation of the EU
> EU NAVFOR Somalia
>
> This military operation, called EU NAVFOR Somalia - operation
> "Atalanta", is launched in support of Resolutions 1814 (2008), 1816
> (2008), 1838 (2008) and 1846 (2008) of the United Nations Security Council (UNSC) in order to contribute to:
> - the protection of vessels of the WFP (World Food Programme) delivering food aid to displaced
> persons in Somalia;
> - the protection of vulnerable vessels cruising off the Somali coast, and the deterrence, prevention
> and repression of acts of piracy and armed robbery off the Somali coast.
> This operation, which is the first EU maritime operation, is conducted
> in the framework of the European Security and Defence Policy (ESDP).
>
>
> More information and background documents available on
> http:// gnarus.mobi/media/EuropeanUnion_MilitaryOperations_EN. zip
> and
> http:// quimeras.com.mx/media/EuropeanUnion_MilitaryOperations_EN. zip
>
> ________________________________________
> PRESS - EU Council Secretariat Tel: +32 (0)2 281 7640 / 6319
Headers
X-VirusChecked: Checked
X-Env-Sender: gnarusm@mail.thecopperstar.com
X-Msg-Ref: xxxxxxxxxxx
X-StarScan-Version: 6.2.4; banners=-,-,-
X-Originating-IP: [174.132.255.10]
X-SpamReason: No, hits=1.0 required=7.0 tests=BODY_RANDOMQ
Received: (qmail 15068 invoked from network); 26 Aug 2010 13:24:33 -0000
Received: from a.ff.84ae.static.theplanet.com (HELO mail.thecopperstar.com)
(174.132.255.10) by xxxxxxxxxx
DHE-RSA-AES256-SHA encrypted SMTP; 26 Aug 2010 13:24:33 -0000
Received: from gnarusm by mail.thecopperstar.com with local (Exim 4.69)
(envelope-from <gnarusm@mail.thecopperstar. com>) id
1OocRS-0006Y5-PR for
XXXXXXXXXX; Thu, 26 Aug 2010 08:24:30 -0500
To: XXXXXXXXX
Subject: From Intelligence Fusion Centre to XXXXXXX
From: <ifc@ifc.nato.int>
Message-ID: <E1OocRS-0006Y5-PR@mail. thecopperstar.com>
Date: Thu, 26 Aug 2010 08:24:30 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - mail.thecopperstar.com
X-Env-Sender: gnarusm@mail.thecopperstar.com
X-Msg-Ref: xxxxxxxxxxx
X-StarScan-Version: 6.2.4; banners=-,-,-
X-Originating-IP: [174.132.255.10]
X-SpamReason: No, hits=1.0 required=7.0 tests=BODY_RANDOMQ
Received: (qmail 15068 invoked from network); 26 Aug 2010 13:24:33 -0000
Received: from a.ff.84ae.static.theplanet.com (HELO mail.thecopperstar.com)
(174.132.255.10) by xxxxxxxxxx
DHE-RSA-AES256-SHA encrypted SMTP; 26 Aug 2010 13:24:33 -0000
Received: from gnarusm by mail.thecopperstar.com with local (Exim 4.69)
(envelope-from <gnarusm@mail.thecopperstar.
XXXXXXXXXX; Thu, 26 Aug 2010 08:24:30 -0500
To: XXXXXXXXX
Subject: From Intelligence Fusion Centre to XXXXXXX
From: <ifc@ifc.nato.int>
Message-ID: <E1OocRS-0006Y5-PR@mail.
Date: Thu, 26 Aug 2010 08:24:30 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - mail.thecopperstar.com
174.132.255.10
Hostname: a.ff.84ae.static.theplanet.com
ISP: THEPLANET.COM INTERNET SERVICES
Organization: THEPLANET.COM INTERNET SERVICES
Type: Broadband
Assignment: Static IP
Country: United States
State/Region: Texas
ISP: THEPLANET.COM INTERNET SERVICES
Organization: THEPLANET.COM INTERNET SERVICES
Type: Broadband
Assignment: Static IP
Country: United States
State/Region: Texas
http://www.virustotal.com/file-scan/report.html?id=5761e303d7bc027df47b5b01a3e4e8e186eb36d3a4f40956768231ef3bbcac46-1282832496
Submission date: 2010-08-26 14:21:36 (UTC)
Current status: finished
Result: 11 /41 (26.8%)
Avast 4.8.1351.0 2010.08.26 PDF:Risk-A
Avast5 5.0.594.0 2010.08.26 PDF:Risk-A
BitDefender 7.2 2010.08.26 Exploit.PDF-Dropper.Gen
eSafe 7.0.17.0 2010.08.26 PDF.DropperExploit.Gen
eTrust-Vet 36.1.7818 2010.08.26 PDF/Pidief.RU
F-Secure 9.0.15370.0 2010.08.26 Exploit.PDF-Dropper.Gen
GData 21 2010.08.26 Exploit.PDF-Dropper.Gen
Kaspersky 7.0.0.125 2010.08.26 Trojan-Dropper.VBS.Pdfka.b
nProtect 2010-08-26.01 2010.08.26 Exploit.PDF-Dropper.Gen
PCTools 7.0.3.5 2010.08.26 Trojan.Dropper
SUPERAntiSpyware 4.40.0.1006 2010.08.26 -
Symantec 20101.1.1.7 2010.08.26 Trojan.Dropper
Additional informationShow all
MD5 : 8b3a3c4386e4d59c6665762f53e6ec8e
/Type /Action
/S /Launch
/Win /F (cmd.exe)
/P (
/c echo Dim BinaryStream > vbs1.vbs && echo Set BinaryStream = CreateObject("ADODB.Stream")
-------------------------------------------------
Windows XPSP2 Adobe Reader 9.1
Quick flash of CMD.exe black window and we are looking at a pretty new icon on the desktop exe.exe
Files created
c:\windows\system32\ntos.exe 28C4648F05F46A3EC37D664CEE0D84A8
same directory as the original file - exe.exe 5fb94eef8bd57fe8e20ccc56e33570c5
And these are the classic signs of old Zeus and this is what it is.
File name:
exe.exe
http://www.virustotal.com/file-scan/report.html?id=33ac66e78d410d03f5644fb1569ea7d28e823561e00b86593d9022f554127c7e-1282847843
3 /41 (7.3%)
AntiVir 8.2.4.46 2010.08.26 TR/Crypt.XPACK.Gen2
PCTools 7.0.3.5 2010.08.26 Trojan.Zbot
Symantec 20101.1.1.7 2010.08.26 Trojan.Zbot
Additional information
Show all
MD5 : 5fb94eef8bd57fe8e20ccc56e33570c5
File name: ntos.exe
http://www.virustotal.com/file-scan/report.html?id=c61fdc96fb7861396d7aa99a26cb6dff3f92aeeccf93d212a8fa3e166adec6aa-1282850806
Submission date: 2010-08-26 19:26:46 (UTC)
Result: 4 /39 (10.3%)
AntiVir 8.2.4.46 2010.08.26 TR/Crypt.XPACK.Gen2
Panda 10.0.2.7 2010.08.26 Suspicious file
PCTools 7.0.3.5 2010.08.26 Trojan.Zbot
Symantec 20101.1.1.7 2010.08.26 Trojan.Zbot
Additional informationShow all
MD5 : 28c4648f05f46a3ec37d664cee0d84a8
Aug 26 CVE-2009-4324 Chess on the High Seas from matthewgebert@yahoo.com 113.30.106.22
Download 43cb55861b7fcf1dfb6968c9ef110bcc Aug2010.pdf as a password protected archive (contact me if you need the password)
From: Matthew Gebert [mailto:matthewgebert@yahoo.com]
Sent: Thursday, August 26, 2010 10:11 PM
To: matthewgebert@yahoo.com
Subject: Chess on the High Seas - Dangerous Times for U.S.-China Relations
The Obama administration's hopes that its warmer approach to Beijing would yield a more fruitful Sino-American relationship have been disappointed. Rather than adopting a more cooperative bearing, Beijing has become increasingly assertive over the past year. Recognizing the resulting detriment to U.S. interests and Asia-Pacific peace and security, the Obama administration is now pushing back. This new direction may convince Beijing to reconsider its recent assertive policies, but for now, the United States and China have entered a period of tense relations, raising the odds of a true crisis. Particularly worrisome is Chinese media coverage of this summer's quarrels, which has been nationalistic and anti-American in tone and content. Such coverage makes conflicts more difficult to resolve, as the Chinese regime cannot afford to look weak in the eyes of an incensed citizenry. Policymakers in both countries should be aware of this dynamic as they approach any additional disputes in the coming months.
Key points in this Outlook:
• The United States and China have clashed over maritime exercises, with Beijing opposed to Washington asserting its right to exercise in international waters.
• The Chinese media responded with a stream of nationalistic, anti-American reporting--portraying the United States as an imperial power.
• Despite China's confidence, there are signs of internal weakness in the People's Republic, with social unrest on the rise
• The United States should prepare diplomati¬cally and militarily for a potential crisis.
File name:
Aug2010.pdf
Submission date:
2010-08-29 03:33:46 (UTC)
http://www.virustotal.com/file-scan/report.html?id=a74996d152e867a8bc9a7585a622bab3fdf7c792d9ed16d3fd07643bbec2cfff-1283052826
Result:
24 /41 (58.5%)
AntiVir 8.2.4.46 2010.08.28 EXP/Pdfka.otd.2
Antiy-AVL 2.0.3.7 2010.08.26 Exploit/Win32.Pidief
Authentium 5.2.0.5 2010.08.28 PDF/Obfusc.M!Camelot
Avast 4.8.1351.0 2010.08.28 JS:Pdfka-WJ
Avast5 5.0.594.0 2010.08.28 JS:Pdfka-WJ
AVG 9.0.0.851 2010.08.28 Script/Exploit
BitDefender 7.2 2010.08.29 Exploit.PDF-JS.Gen
ClamAV 0.96.2.0-git 2010.08.28 Suspect.PDF.ObfuscatedJS-5
DrWeb 5.0.2.03300 2010.08.29 Exploit.PDF.1386
Emsisoft 5.0.0.37 2010.08.28 Exploit.Win32.Pidief!IK
eTrust-Vet 36.1.7823 2010.08.27 PDF/Utild.A
F-Prot 4.6.1.107 2010.08.28 JS/ShellCode.AV.gen
F-Secure 9.0.15370.0 2010.08.28 Exploit.PDF-JS.Gen
GData 21 2010.08.29 Exploit.PDF-JS.Gen
Ikarus T3.1.1.88.0 2010.08.28 Exploit.Win32.Pidief
Kaspersky 7.0.0.125 2010.08.29 Exploit.Win32.Pidief.dcw
Microsoft 1.6103 2010.08.28 Exploit:Win32/Pdfjsc.FE
NOD32 5405 2010.08.28 JS/Exploit.Pdfka.OAQ
Norman 6.05.11 2010.08.28 PDF/Exploit.EK
nProtect 2010-08-28.01 2010.08.28 Exploit.PDF-JS.Gen
Panda 10.0.2.7 2010.08.28 Exploit/PDF.Gen.B
Sophos 4.56.0 2010.08.28 Troj/PDFJs-LP
Sunbelt 6808 2010.08.29 Exploit.PDF-JS.Gen (v)
TrendMicro-HouseCall 9.120.0.1004 2010.08.29 Expl_ShellCodeSM
Additional information
Show all
MD5 : 43cb55861b7fcf1dfb6968c9ef110bcc
Metadata
ModifyDate>2009-12-22T11:36:33+08:00
CreateDate>2009-07-08T10:53:46+08:00
MetadataDate>2009-12-22T11:36:33+08:00
Wepawet
http://wepawet.cs.ucsb.edu/view.php?hash=43cb55861b7fcf1dfb6968c9ef110bcc&type=js
Vicheck
https://www.vicheck.ca/md5query.php?hash=43cb55861b7fcf1dfb6968c9ef110bcc
Headers
Received: from n9.bullet.mail.ac4.yahoo.com (HELO n9.bullet.mail.ac4.yahoo.com) (76.13.13.237)
by XXXXXXXX with SMTP; 27 Aug 2010 02:11:07 -0000
Received: from [76.13.13.26] by n9.bullet.mail.ac4.yahoo.com with NNFMP; 27 Aug 2010 02:11:07 -0000
Received: from [67.195.9.82] by t3.bullet.mail.ac4.yahoo.com with NNFMP; 27 Aug 2010 02:11:06 -0000
Received: from [98.137.27.128] by t2.bullet.mail.gq1.yahoo.com with NNFMP; 27 Aug 2010 02:11:05 -0000
Received: from [127.0.0.1] by omp202.mail.gq1.yahoo.com with NNFMP; 27 Aug 2010 02:11:05 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 802667.36531.bm@omp202.mail.gq1.yahoo.com
Received: (qmail 72747 invoked by uid 60001); 27 Aug 2010 02:11:04 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1282875064; bh=l9AXsT5C8sF+Wj3+wZuf66KGHc9tCySFLnfUCWLNbP4=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=5lAniIl4dUviz+2ztqdLBTUv2dJJosRNUFwUA6v5b6Bv91c0xc3X2+iQi0lmA/u2zhBbdkpa/7kkRFxOwQ37Yug0Yz87x46EFqWnc7nj6NryiKtw5IwQQrmjbYis5+iUrM0+vIGFWDsafRccUMM2JLMcMmyuAwtWo2V306eDxuY=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type;
b=fyoCJ/7uWzk719SN6brIlyQpRM7DTUGHl3avD700M0W5g/8I8sy2taVIo3hUOtw5hJpy7AK7cB8uwMny2YQl/5gnaCSvogE9ZyOkTPe8VMYe+TCNJzOjcYSTpvWwCyY/HxWA/PM3pikcpAjWICDGaCGteXVewpEd7/UyO+F00eA=;
Message-ID: <520863.70331.qm@web120012.mail.ne1.yahoo.com>
X-YMail-OSG: Cg7zbwIVM1n3PDFvLIg7lltCnqUSL4y_NlzOFZE1zbiyDxr
85gBGwOK1IbPQvo.9Hs2KWuieNkJFhApgm0ANFIB7L.bxG2QGqH7_XY9oix7
hlESdD6YZrxr3Vw7Z5IbQUYLcVXpHI17096rHp_WSYX7foGEcAtyhxI_d7m9
2.rOb6nWEuT6n_aOT3YujB85FSo9wvI8FRD4LJaA-
Received: from [113.30.106.22] by web120012.mail.ne1.yahoo.com via HTTP; Thu, 26 Aug 2010 19:11:04 PDT
X-Mailer: YahooMailClassic/11.3.2 YahooMailWebService/0.8.105.279950
Date: Thu, 26 Aug 2010 19:11:04 -0700
From: Matthew Gebert
Subject: Chess on the High Seas - Dangerous Times for U.S.-China Relations
To: matthewgebert@yahoo.com
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-52491509-1282875064=:70331"
113.30.106.22
Hostname: 113.30.106.22
ISP: HCLC
Organization: HCLC
Assignment: Static IP
Country: Korea, Republic of
============================================================
Windows XP SP2 Adobe Reader 9.1
Created files
%tmp%\asrss.exe 0 bytes
It needs to be tested on a different VM perhaps, it crashes, so it is hard to tell without further testing or static analysis of the payload
Posted by
Mila
at
12:08 AM
0
comments
Tags:
- ADOBE READER + ACROBAT 8.1.7,
- ADOBE READER + ACROBAT 9.2,
**File-Analysis**,
CVE-2009-4324
Subscribe to:
Posts (Atom)










