2013年11月14日 星期四

old actor, wrong context - hello cannon fodder


We spotted this email few hours ago, the context aligned with the ongoing food safety incidents in Taiwan. However, this email wrongly spell the Ministry of Health and Welfare (衛福部) as Ministry of Medical and Health (醫衛部), which does not exist. (I hope they don't intend to say 一位部, "ministry of only one", it's actually a joke in Chinese - "錦衣衛")



Not surprisingly, one of the recipient found it suspicious and uploaded to VT,




And here is our XecScan results




with PDB string as below:



It says it all, it's 砲灰... "cannon fodder"

2013年11月12日 星期二

[updated: hitting Taiwan too] The recent fresh zero-day targeting Office .docx (CVE-2013-3906)

Watch out~ The recent document exploit CVE-2013-3906 is still a zero-day, it has been over a week, still no patch! By now, we has not witnessed any APT emails hitting Asia carrying this document exploit. However, we believe it's coming soon. [updated] Government agencies in Taiwan are starting to get this document exploit, roughly a week after the security advisory. If you happened to spot any more suspicious ones, feel free to dump to our online XecScan (http://scan.xecure-lab.com), it would digest this document exploit happily, as always.
[This is advertisement] For our XecMail customers, no worry, this zero day would get detected without any engine update. :)

2013年11月11日 星期一

[台灣也中了] 最新的Document Exploit CVE-2013-3906 請大家注意新一波的攻擊

首先我很抱歉,很久沒寫新的文章, 就連美國的Blackhat 2013都還欠大家一篇遊記 ,很快會補上~

各位請特別注意,最近出現新的Document Exploit, CVE-2013-3906, 而且目前 Zero-day, 還沒有patch可以用!(已經過了一個禮拜還沒有patch可以用,只能請各位施主燒香自我祈福) 可怕的是這次是很少見針對Office 2007 格式 (DOCX)的惡意文件, 目前在國外已經是腥風血雨,很快的我們在亞洲應該會看到, 現在掃毒軟體的偵測率還非常的低, 請嚴防豪雨 !

我們的XecScan是目前唯一可以分析該樣本的線上服務系統,如果有發現可疑檔案,請上傳 http://scan.xecure-lab.com

[廣告] XecMail 用戶不用更新即可偵測該Zero Day :)


2013年6月14日 星期五

PDF exploit is getting hot, watch out for CVE-2013-2729

There are at least three hot document exploits shooting around on this season, mainly disguised in the form of .doc and .pdf document. Earlier this month, we identified an interesting PDF file, pretty fresh, it's the CVE-2013-2729 exploit, which was recently patched by Adobe on May 14, http://www.adobe.com/support/security/bulletins/apsb13-15.html. The first security advisory of this exploit was released by http://www.binamuse.com, it's a specially crafted BMP file that can bypass ASLR and DEP!

提醒大家新的APT高峰期即將出現, 新 PDF Exploit CVE-2013-2729 已經用在 APT Email 攻擊中

提醒大家新的APT高峰期即將出現,目前至少有3個惡意文件的Exploit正在流行,目前以DOC跟PDF為主,首先下面我們介紹一下這一梯的 PDF 新貨 :)

CVE-2013-2729 是一個才在5月14號被Adobe最新修補的 PDF漏洞,最早發表研究的是 http://www.binamuse.com,透過一個特別設計的BMP檔引發漏洞,這個exploit 可以繞過ASLR+DEP 成功達陣! 影響Adobe Reader XI (11.0.02)之前的版本。請參考 http://www.adobe.com/support/security/bulletins/apsb13-15.html

2013年5月1日 星期三

HITCON 2013 Call For Paper !!! 第九屆台灣駭客年會公開徵稿 !!!


第九屆台灣駭客年會將於 2013 年 7 月 19~20 日(週五、六)中央研究院人文社會科學館舉行,為因應今年國際資安事件頻傳,除了網路間諜行動越演越烈之外,甚至逐漸轉向為能夠影響一國政經情勢之資訊戰態勢,HITCON 籌辦委員會為提升國內資安能量,並厚植國內資安人才,今年特擴大舉辦徵稿,內容涵蓋資訊安全技術、關鍵基礎保護、資訊法規政策、資安人才培育及相關研究論文等,歡迎各界人士踴躍投稿。

為使審核標準與流程一致,HITCON 今年首次使用稿件管理系統收稿,請欲投稿者於 2013年 6 月 30 日前,至(http://cfp2013.hitcon.org)註冊相關資訊與上傳稿件,俾利議程委員審核。

為鼓勵投稿,本次會議將於發表當日致贈每篇被接受之論文 NT$3,000 元整。此外,大會將依作者意願,將論文或演講內容以電子或書面媒體方式散佈。

除了上述的論文徵求外,本次駭客年會計畫了一場 0-day exploit 展示,只要在 2013 年 6 月 15 日前,將您個人所發現的漏洞(未公開且尚未被修正),以電子郵件方式傳送至 agenda2013 [at] hitcon.org,經過確認,就有機會免費取得本屆駭客年會的入場券,並且上台展示漏洞,該漏洞一切權利歸作者所有。