Categorized | Microsoft

Very bad news, with more bad news embedded

Malware writers never miss the chance to take advantage of big world events, no matter how tragic. The recent Japanese nuclear incident, caused by the devastating earthquakes, is their target this time.

The Microsoft Malware Protection Center has been tracking a new backdoor (detected as Backdoor:Win32/Sajdela.A, SHA1 0c3526c7e1d6b8a3d2f5c21986c03f1dc0d88480) that is distributed by utilizing Exploit:Win32/CVE-2010-3333 – code that exploits a previously-addressed RTF parser stack overflow vulnerability in Microsoft Word that may allow remote code execution. (See Microsoft Security Bulletin MS10-087 for additional details and the appropriate update).

The malware arrives on a victims’ system appearing to be a Microsoft Word document (.doc), for example:

The name of this file is in Japanese characters; translated to English it would read “Japan nuclear leakage”. In actual fact, the file is in RTF format.

The following picture illustrates the malicious shell code it contains:

The payload of this malware is an embedded executable file. But to elude a heuristic scanner, the malware erases the PE file signatures (‘MZ’ and ‘PE’).

After successful exploitation, the malware recovers this information before writing the PE file to disk and then executing it.

In order to mislead victims, the malware also drops a hidden Microsoft Word document to “c:\word.doc” and opens it. The content of this file is in Japanese, and is regarding the recent nuclear incident.

This file contains the following file properties:

(A clue to the identity of the malware authors perhaps?)

 

The backdoor component

Installing the backdoor component is the ultimate purpose of this malware. The backdoor component is an encrypted resource inside the malware. When the malware executes, it decrypts the resource and drops it to %SystemRoot\System32\csrls.dll.

The backdoor utilizes control servers at the following locations:

•    24.173.215.70

•    65.5.227.69

The backdoor allows unauthorized access and control of an affected computer, and can be used by a remote attacker to perform actions such as downloading and executing arbitrary files, capturing information and terminating processes.

Using social engineering in this manner to get users to perform actions of the attacker’s choice (for example, opening a file) isn’t news. But when confronted with such a catastrophe, the need for information and reassurance is strong. Don’t forget that attackers will always try to take advantage of human nature. So be careful.

As for the good news – you can keep your system safe from these ill tidings by keeping your antivirus software up to date and ensuring that you apply security updates in a timely fashion.

We will continue to keep you posted.

 

–Zhitao Zhou, MMPC

Related Posts
  • Browser Updates
    Just a few days ago, two major web browsers have been updated to fix security vulnerabilities which may allow attackers to infect the computer with malware just by visiting a hacked website.Google rel...
  • Adobe updates Reader and Acrobat
    A little earlier as announced, Adobe released updated versions of Adobe Acrobat and Reader. These programs were vulnerable to the Flash Player zero-day-vulnerability as well, which was fixed last week...
  • Flash Player Update available
    Just a short notice on the now available Adobe Flash Player Update: Version 10.2.159.1 has been released which fixes the critical security vulnerability which allow attackers to infect computers with ...
  • Another Adobe Flash Zero-Day Found, Embedded in Word Documents
    An exploit for another zero-day vulnerability in Adobe Flash Player was very recently found just a couple of weeks after Adobe patched a similar critical vulnerability, which was actively exploited an...
  • “The Hottest & Funniest Golf Course Video” scam has more than 200,000 likes on Facebook
    Right now there's a scam making its way across Facebook linking to a video titled "The Hottest & Funniest Golf Course Video - LOL" (example screen shot below). Websense customers are...
  • One more Adobe 0-day vulnerability using Office files
    Today Adobe announced a new 0-day vulnerability (CVE-2011-0611) in Adobe Flash Player and Adobe Acrobat that, similar to the previous 0-day from less than a month ago, was found embedded in a Microsof...
  • More on the “massive” SQL injection attack
    Alas, the news was published on April 1st. But it is not a joke. Curious, I spent a bit of time today researching it (when I really was supposed to be doing other things), and while the “lizamoon” ...
  • Facebook HTTPS is a Bit More Done…
    Our February 23rd post noted that Facebook's SSL "Secure Browsing" preferences had some issues remaining persistent. There's been some encouraging progress since then, and this is now what happ...
  • More Browser Updates
    Well, actually we expect some more updates as some security vulnerabilities have been revealed at the Pwn2Own contest during the CanSecWest security conference. Google is the first and pushes out vers...
  • My Facebook profile has been visited more than 15.000 times!
    A friend who is new to Facebook asked, “How is it possible? I just created a Facebook account a few days ago, but my profile has been visited more than 15,000 times. I feel like a celebrity!R...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago