顯示具有 0day 標籤的文章。 顯示所有文章
顯示具有 0day 標籤的文章。 顯示所有文章

2014年4月9日 星期三

注意 CVE-2014-1761 0day exploit 已經大量出現在台灣的APT攻擊

這幾年RTF exploit一值最好用的 apt email才料之一,從CVE-2010-3333到CVE-2012-0158一值以來穩定好觸發,而且容易上手,所以已經是駭客居家旅行必備的殺人兵器 !

這次要跟大家介紹主角是 CVE-2014-1761 是 RTF exploit, 目前還是0day exploit 因為沒有正式的修補程式出來, 屬於駭客快樂假期 !


http://technet.microsoft.com/en-us/security/advisory/2953095 漏洞影響的範圍有 MS-Word 2003,2010,2013 等版本,不過目前看到的樣本都是針對 MS-Word 2010, 在微軟 Microsoft Security Advisory (2953095)中, 我們可以知道這個漏洞是在約 2個星期前被公布 (3/24), 到上周約 4/2 我們才發現國外出現CVE-2014-1706 野外APT樣本, 處發很沒問題, 但是 ROP shellcode 不是針對繁中Office 2010, 所以台灣環境都處發不了, 約昨天(4/8)我們已經發現駭客改版這個樣本, 並換上可以在台灣攻擊的Shellcode, 只花了一個禮拜就完成飛彈改裝, 並且裝上台灣之寶 -- Taidoor !

XecScan系統收到熱心鄉民上傳

6fb4f156ddbf7f2eb678f30e8577910b      兩岸協議監督條例法制化議題彙整.doc (駭客都有在關心台灣,這個題目會不會選的太好)
3e31b13452c4712d8f4214ec6477314f     1030405違規停車通知單.doc

[廣告時間]: 
我們的APT惡意信件偵測系統 XecMail ,不用更新就可以直接偵測到此 0day, 請各位用戶沒事不用找我們 XD


重點整理:
  1. 這次漏洞叫做 CVE-2014-1761, 已經被大量用在APT信件中
  2. 你的 MS-Word 2010 是這次會被攻擊的版本 (Office 2003,2013的免驚)
  3. 目前沒有修補程式, 請期待微軟出, 不過微軟有提到暫時方案: 裝EMET (其實資安廠商都不敢告訴你這個微軟免費工具,其實超他媽強! exploit, shellcode都基本躺平, 裝了之後你家的廢材HIPS/AV可以移除了)

-----

PS: Xecure Lab 已經被國際大廠併購, 現在有了強大的資源挹注, 原團隊不但沒異動,而且還加入更多的資安專家, 共同對於資安研究而努力, 不但將能量行銷到國外, 更希望回饋給台灣資安圈. 我們對於台灣用戶服務不但不變,而且會更升級 ! 

Birdman

2013年11月12日 星期二

[updated: hitting Taiwan too] The recent fresh zero-day targeting Office .docx (CVE-2013-3906)

Watch out~ The recent document exploit CVE-2013-3906 is still a zero-day, it has been over a week, still no patch! By now, we has not witnessed any APT emails hitting Asia carrying this document exploit. However, we believe it's coming soon. [updated] Government agencies in Taiwan are starting to get this document exploit, roughly a week after the security advisory. If you happened to spot any more suspicious ones, feel free to dump to our online XecScan (http://scan.xecure-lab.com), it would digest this document exploit happily, as always.
[This is advertisement] For our XecMail customers, no worry, this zero day would get detected without any engine update. :)

2013年11月11日 星期一

[台灣也中了] 最新的Document Exploit CVE-2013-3906 請大家注意新一波的攻擊

首先我很抱歉,很久沒寫新的文章, 就連美國的Blackhat 2013都還欠大家一篇遊記 ,很快會補上~

各位請特別注意,最近出現新的Document Exploit, CVE-2013-3906, 而且目前是 Zero-day, 還沒有patch可以用!(已經過了一個禮拜還沒有patch可以用,只能請各位施主燒香自我祈福) 可怕的是這次是很少見針對Office 2007 格式 (DOCX)的惡意文件, 目前在國外已經是腥風血雨,很快的我們在亞洲應該會看到, 現在掃毒軟體的偵測率還非常的低, 請嚴防豪雨 !

我們的XecScan是目前唯一可以分析該樣本的線上服務系統,如果有發現可疑檔案,請上傳 http://scan.xecure-lab.com

[廣告] XecMail 用戶不用更新即可偵測該Zero Day :)


2013年6月14日 星期五

PDF exploit is getting hot, watch out for CVE-2013-2729

There are at least three hot document exploits shooting around on this season, mainly disguised in the form of .doc and .pdf document. Earlier this month, we identified an interesting PDF file, pretty fresh, it's the CVE-2013-2729 exploit, which was recently patched by Adobe on May 14, http://www.adobe.com/support/security/bulletins/apsb13-15.html. The first security advisory of this exploit was released by http://www.binamuse.com, it's a specially crafted BMP file that can bypass ASLR and DEP!

2012年8月28日 星期二

請注意,最新的 CVE-2012-1535 已經廣泛運用於APT惡意文件中

最新的  CVE-2012-1535 已經廣泛運用於APT惡意文件中 !

我知道大家最近都在忙著幫警察伯伯找李X瑞的風雅影片,但是還是得要煞風景地提醒大家 APT的攻擊活動與兼賣賣菜 :)

在 8月 16號, 公布了一個Adobe Flash的弱點 APSB12-18 http://www.adobe.com/support/security/bulletins/apsb12-18.html
也就是 CVE-2012-1535,很快的駭客在1,2天內研發出可利用的Exploit,同時各種產生器也出現在網路上,並開始大量流行於APT攻擊活動中。而Mila 也在 http://contagiodump.blogspot.tw/2012/08/cve-2012-1535-samples-and-info.html 也在8/17 公布了一些研究用的樣本,有興趣的朋友可以看看。

這個弱點攻擊的是 Adobe Flash Player 11.3.300.270,對很多人來說已經是很新的版本,居然也會被攻擊,大家更要提高警覺。

從上禮拜開始,我們客戶陸續回報出這個新攻擊給Xecure Lab, XecMail 與 XecScan 不需要任何更新,就可以在第一時間偵測與分析此新的 Exploit。


已經過了這麼多天了,到目前為止42加防毒業者中僅只6,7家可以偵測,可以辨識CVE編號的只有4家可以偵測此 APT攻擊文件...
在台灣最常用的幾家掃毒幾乎都 GG了,像是政府機關裝最多的趨勢科技、個人用戶最愛的小紅傘、F-Secure、甚至 Macfee與 微軟的掃毒引擎。 全部都不支倒地,挫在等。大廠中只有 Kasperky與 Symantect算是比較認真有在上班的,目前都可以偵測到。

根據許多的研究與駭客討論顯示,請大家特別注意的攻擊還有 Java的 0Day Exploit與mscomctl.ocx (KB2597986 MS12-060) ,很快的會變成下一波 APT的主打歌。

目前正是APT惡意郵件活動的高峰期... 絕對要嚴防豪雨 !!

Birdman,
Xecure Lab

2012年5月21日 星期一

Malicious PDF used in APT attacks exploiting new variants of CVE-2012-0754

Xecure Lab has discovered a new CVE-2012-0754 Flash player exploit variant being used in recent APT activities. The earliest version came from a Word document named "Iran's Oil and Nuclear Situation.doc" (see Mila's blog), where the embedded Flash codes would download an MP4 file from a remote server that contains the actual exploit codes for triggering the Flash bug. Today, the new variant we found is a malicious PDF and the MP4 is self-contained in the PDF!

2012年4月16日 星期一

New RTF Exploit CVE-2012-0158 has been discovered in real-world APT attacks!

We have discovered new exploit (CVE-2012-0158) in APT emails!

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0158










This RTF vulnerability was just patched in Apr. 10 as MS12-027.
Microsoft Security Bulletin MS12-027 -
Critical Vulnerability in Windows Common Controls
Could Allow Remote Code Execution (2664258)
http://technet.microsoft.com/en-us/security/bulletin/ms12-027

RTF File:











At this moment, the new exploit enjoys a very low AV detection rate
on VirusTotal, with only 2 out of the 42 antivirus engines flagging it as malicious.

2011年12月13日 星期二

Adobe failed to patch the U3D 0day Exploit (CVE-2011-2462) on time as promised

Xecure Lab's free online APT scanning service - XecScan (http://scan.xecure-lab.com) successfully identified a new vulnerability being actively exploited in targeted attack and Adobe had released security advisory of this critical issue as the U3D memory corruption vulnerability (CVE-2011-2462).

Originally, Adobe aims to make an update for Adobe Reader 9.x and Acrobat 9.x for Windows no later than the week of December 12, 2011, however a security patch for CVE-2011-2462 is still not yet available.

For the past one week, we have received three different md5 version of the APT samples, however they all point to the same known APT attack group.


As it's U3D vulnerability, we found all samples have the U3D-related strings.

MD5 of our CVE-2011-2462 samples:
  1. 409256cfdeb1932392aa7e63ccb38644
  2. c72484172babcc53fcb28e9427283d95
  3. 721fda5df552f4130218ad9bd2a4ab78
Suggestions for Mitigation:

  • If you're our XecMail customer, there is nothing to be worried, such APT emails would be identified.
  • If you favor manual inspection, please look for U3D-related patterns.
  • Once again, there is always our free XecScan service that you can leverage to scan any suspicious document.
  • Lastly, the official patch from Adobe should be available pretty soon.






We have free anti-APT services for the community:

  • XecMail Cloud is online APT scanning service for your Gmail account.
  • XecScan is online APT scanning service for your local document.