On Metacritic: Who will grab the Best Picture trophy?
BNET Business Network:
BNET
TechRepublic
ZDNet

February 17th, 2009

Targeted malware attacks exploiting IE7 flaw detected

Posted by Dancho Danchev @ 4:57 pm

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Exploit code, Hackers, Malware, Microsoft, Passwords

Tags: Security, Targeted Attack, Chinese Hackers, Internet Explorer Vulnerability, MS09-002, Dancho Danchev

Researchers at TrendMicro have detected a targeted malware attack exploiting last week’s patched critical MS09-002 vulnerability affecting Internet Explorer 7.  Upon opening the spammed Microsoft office document, vulnerable users are automatically forwarded to a Chinese live exploit site which still remains active.

The attack has also been confirmed by McAfee and by the ISC, who point out that the cybercriminals appear to have reverse engineered Microsoft’s patch in order to come up with the exploit.

From TrendMicro’s post:

The threat starts with a spammed malicious .DOC file detected as XML_DLOADR.A. This file has a very limited distribution script, suggesting it may be a targeted attack. It contains an ActiveX object that automatically accesses a site rigged with a malicious HTML detected by the Trend Micro Smart Protection Network as HTML_DLOADER.AS.

HTML_DLOADER.AS exploits the CVE-2009-0075 vulnerability, which is already addressed by the MS09-002 security patch released last week. On an unpatched system though, successful exploitation by HTML_DLOADER.AS downloads a backdoor detected as BKDR_AGENT.XZMS.

This backdoor further installs a .DLL file that has information stealing capabilities. It sends its stolen information to another URL via port 443.

The attackers trade-off in this case is to either launch a less noisy targeted attack, or attempt to target as many users as possible by using legitimate web sites as infection vectors, a choice that depends on what they’re trying to achieve, and who are they targeting in particular.

Who’s behind the attack anyway? The web service (9966.org) used as a “phone back” location with the stolen data, is a well known one used primarily by Chinese hackers in previous massive SQL injections attacks, which doesn’t necessarily mean the campaign is launched by Chinese hackers, since it could be international hackers from anywhere using a well known malicious infrastructure in order to forward the responsibility to local hackers.

Moreover, in this particular campaign I can easily argue that the window of opportunity for abusing this vulnerability in a targeted fashion, is just as wide open as attempting to exploit the same hosts by diversifying the use of different exploits. For instance, despite the timely exploitation of MS09-002, based on the number of Conficker affected hosts globally, a situation where once again a patch is present, there’s a great chance that some of the hosts they’re attempting to exploit through the use of MS09-002 are already part of Conficker’s botnet, or remain susceptible to outdated vulnerabilities.

So far, no massive malware campaigns are taking advantage of the exploit, but users are advised to self-audit themselves against known client-side vulnerabilities and MS09-002 in particular.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 47 Talkback(s)
"tired of the Apache server crap ..."
It really annoys some of the MS fanboys --- we know. To call Apache as "dominant," would be a stretch. But it"prominent" (at least in the server market) is anything but inaccurate. "Tired" of that fac... (Read the rest)
Posted by: brian ansorge Posted on: 04/15/09 You are currently: a Guest | | Terms of Use
Thanks for the heads up.  kozmcrae | 02/17/09
RE: Targeted malware attacks exploiting IE7 flaw detected  Loverock Davidson | 02/17/09
Why is the exploit even there to begin with? (NT)  kozmcrae | 02/17/09
Sadly  honeymonster | 02/17/09
RE: Sadly, can you ...  n0neXn0ne | 02/18/09
Just do not confuse  honeymonster | 02/18/09
I think his point was that....  storm14k | 02/18/09
Fair enough  honeymonster | 02/18/09
Neutering nOneXnOne - Security by Obscurity PROVEN  PMC-CON | 02/19/09
@PMC-CON  Axsimulate | 02/20/09
Responsible Disclosure  jbroche18 | 02/22/09
I'm so sick of ignorance.....  Crestview | 02/18/09
What kind of jerk replies like that?  Timewellwasted | 02/18/09
Thats what you would like to think  Crestview | 02/18/09
Message has been deleted  honeymonster | 02/17/09
FOR THE LOVE OF GOD WHEN DOES THIS ALL END!  Intellihence | 02/18/09
First of all  honeymonster | 02/18/09
I'm no longer buying that market share C.R.A.P.  Intellihence | 02/18/09
Riiiiight.  NStalnecker | 02/18/09
As a Mac user since the mid 90's  Intellihence | 02/18/09
And as a Windows user  NStalnecker | 02/18/09
You have your limitations on Windows  Intellihence | 02/18/09
I wish people would learn this  Crestview | 02/18/09
Your day is coming...  Crestview | 02/18/09
Security by Obscurity -- Read The Link  PMC-CON | 02/19/09
You can believe/buy want you want  honeymonster | 02/18/09
Dude it's been a long 14 years  Intellihence | 02/18/09
Ignorance is bliss...  NStalnecker | 02/18/09
It's been a BLISSFUL 14 years, really it has been.  Intellihence | 02/18/09
I'm a quarter century on Macs  macadam | 02/18/09
14 years  Cyrorm | 02/18/09
Or how stupid 100% of Mac users are  Crestview | 02/18/09
Where did you get those numbers?  linux for me | 02/18/09
Actually  NStalnecker | 02/18/09
Intellihence:  justanitguy | 02/18/09
Look....  Crestview | 02/18/09
At least MS patches vulns before they are exploited  NonZealot | 02/18/09
RE: Targeted malware attacks exploiting IE7 flaw detected  rMatey | 02/18/09
Ignorance still prevails....  Crestview | 02/18/09
are the Chinese hackers  walkerjian@... | 02/18/09
RE: Targeted malware attacks exploiting IE7 flaw detected  gabrielbear@... | 02/18/09
Marketshare Myth 101  brian ansorge | 02/18/09
Neutering brian ansorge - It's 100% Market Share  PMC-CON | 02/19/09
"tired of the Apache server crap ..."  brian ansorge | 04/15/09
Why is this also not a Word Flaw?  PMC-CON | 02/19/09
Balls of steel  brian ansorge | 02/19/09
RE: Targeted malware attacks exploiting IE7 flaw detected  BobP500 | 02/23/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here