Common Vulnerabilities and Exposures (CVE)number
CVE-2011-0611
This vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system.
General File Information
File 1
File Disentangling Industrial Policy and Competition Policy.doc
MD5 96cf54e6d7e228a2c6418aba93d6bd49
SHA1 820699d9999ea3ba07e7f0d0c7f08fe10eae1d2d
File size : 176144 bytes
Type: DOC with SWF
Distribution: Email attachment
File 2
File Japan Nuclear Weapons Program.doc
MD5 78C628FC44FE40BFF47176613D3E1776
File size : 167440 bytes
Type: DOC with SWF
Distribution: Email attachment
File 3
File Message from Anne.doc
MD5 A51EDD010F3C0D33249BE771891265CB
SHA1 820699d9999ea3ba07e7f0d0c7f08fe10eae1d2d
File size : 167440 bytes
Type: DOC with SWF
Distribution: Email attachment
File 4
this file has been first detected on or before April 12 (thanks to anonymous for the donation)
File JOB_DESCRIPTION.doc
MD5 9bdefcc465c73fc5eedf41ebf47b5f6c
SHA1 6f969aad92fe9340d00b31eab95355088767b9ed
File size : 167440 bytes
Type: DOC with SWF
Distribution: Email attachment
File 5
this file has been first detected on or before April 11 (thanks to anonymous for the donation)
File plan.doc
MD5 d1bfe000e745207c32343bfe5abd94c9
SHA1 45573ee5d89c1d7e7adb98149cca2dfee48b5d1f
File size : 186896 bytes
Type: DOC with SWF
Distribution: Email attachment
File 6
this file has been first detected on April 14
File namelist.xls
MD5 aaff5eabe5d803742dbb8b405e7a7c4cb659f12c
SHA1 45573ee5d89c1d7e7adb98149cca2dfee48b5d1f
File size : 162316 bytes
Type: XLS with SWF
Distribution: Email attachment
File 7
this file has been first detected on April 15
File Response 2011.doc
MD5 a421d074611188cfcfcedba55cc7e194
SHA1 ca044e91761e633a0580c947adc39a6ca248e5e9
File size : 167440 bytes
Type: DOC with SWF
Distribution: Email attachment
Download
The recipients of this message included people whose names you can find in Wikipedia and assistants of
former high ranked politicians who are now working at global consulting
companies.
Using "volatility" to study the CVE-2011-6011 Adobe Flash 0-day by Andre' DiMino
Please see analysis of the exploit code at http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html by Villy
Disentangling Industrial Policy and Competition Policy.swf - Trojan-Dropper.MSWord.SwfDrop.a by Kimberly
Update April 29, 2011
According to Cédric Gilbert (SkyRecon R&D), the shellcode’s last command include a “taskkill /im hwp.exe”. This hwp.exe file could be related to a South-Korean Word Processor Software :
“Hangul Word Processor or HWP”. According to Wikipedia :
“Hangul Word Processor or HWP”. According to Wikipedia :
“It is used extensively in South Korea, especially by the government.“
Which could match a targeted attack towards this region.
According to Hangul’s website, this word processor handle Microsoft .DOC & .DOCX documents.
So the questions are
- Is the infected doc with zero-day also ‘compatible’ with it ?
- Was it used in Korea?
- Was it made in Korea?
Your comments and thoughts are welcome.
thanks,
Mila
Using "volatility" to study the CVE-2011-6011 Adobe Flash 0-day by Andre' DiMino
Disentangling Industrial Policy and Competition Policy.swf - Trojan-Dropper.MSWord.SwfDrop.a by Kimberly





