Targeted malware attacks exploiting IE7 flaw detected
Researchers at TrendMicro have detected a targeted malware attack exploiting last week’s patched critical MS09-002 vulnerability affecting Internet Explorer 7. Upon opening the spammed Microsoft office document, vulnerable users are automatically forwarded to a Chinese live exploit site which still remains active.
The attack has also been confirmed by McAfee and by the ISC, who point out that the cybercriminals appear to have reverse engineered Microsoft’s patch in order to come up with the exploit.
From TrendMicro’s post:
The threat starts with a spammed malicious .DOC file detected as XML_DLOADR.A. This file has a very limited distribution script, suggesting it may be a targeted attack. It contains an ActiveX object that automatically accesses a site rigged with a malicious HTML detected by the Trend Micro Smart Protection Network as HTML_DLOADER.AS.
HTML_DLOADER.AS exploits the CVE-2009-0075 vulnerability, which is already addressed by the MS09-002 security patch released last week. On an unpatched system though, successful exploitation by HTML_DLOADER.AS downloads a backdoor detected as BKDR_AGENT.XZMS.
This backdoor further installs a .DLL file that has information stealing capabilities. It sends its stolen information to another URL via port 443.
The attackers trade-off in this case is to either launch a less noisy targeted attack, or attempt to target as many users as possible by using legitimate web sites as infection vectors, a choice that depends on what they’re trying to achieve, and who are they targeting in particular.
Who’s behind the attack anyway? The web service (9966.org) used as a “phone back” location with the stolen data, is a well known one used primarily by Chinese hackers in previous massive SQL injections attacks, which doesn’t necessarily mean the campaign is launched by Chinese hackers, since it could be international hackers from anywhere using a well known malicious infrastructure in order to forward the responsibility to local hackers.
Moreover, in this particular campaign I can easily argue that the window of opportunity for abusing this vulnerability in a targeted fashion, is just as wide open as attempting to exploit the same hosts by diversifying the use of different exploits. For instance, despite the timely exploitation of MS09-002, based on the number of Conficker affected hosts globally, a situation where once again a patch is present, there’s a great chance that some of the hosts they’re attempting to exploit through the use of MS09-002 are already part of Conficker’s botnet, or remain susceptible to outdated vulnerabilities.
So far, no massive malware campaigns are taking advantage of the exploit, but users are advised to self-audit themselves against known client-side vulnerabilities and MS09-002 in particular.




Hi everyone. Those are my principles, and if you don't like them... well, I have others.
I am from Laos and also now teach English, give please true I wrote the following sentence: "Keywords - cheap airline tickets; dirt cheap airline tickets; airline tickets cheap last minute; really cheap airline tickets; very cheap airline tickets."
Best regards
Reply to this
Thanks for sharing this information
Reply to this
Useful information like this one must be kept and maintained so I will put this one on my bookmark list! Thanks for this wonderful post and hoping to post more of this!
Reply to this
Hi everyone.Thanks for sharing this information.
Reply to this
that was a great posting made by the red_65, that is really the great one.
Reply to this
Thank you, I love to read articles that are informative and beneficial in nature.
Reply to this
Nice post! I loved it your way of information.. I need more tips for this.. Can you provide more information for this?
Reply to this
Excellent blog post, I look forward to reading more.
Reply to this
The government Grants Blog had an interesting article the other day on how your weight can affect whether you get a grant or not. Thankfully, I got about 2 body wraps the other day and i gave my uncle some weight loss info because he needs to use that coal bucket at work later.
Reply to this
Thanks for this from all of our friends and sponsors
Payday Loans Direct Lender | as seen on tv | Directory Submission | seo services | Facilities Management Jobs | how to grow taller | web hosting reviews
Reply to this
That is some inspirational stuff. Never knew that opinions could be this varied. Thanks for all the enthusiasm to offer such helpful information here.
Magento Development | Wordpress Development | Joomla Development | Ankylosing spondylitis
Reply to this
No problem. Patch has been out for a week now, the person has to get the document sent to them, accept the big warning saying it might be dangerous to open, then visit the malicious site. This exploit won't go far, if it spreads at all. Hardly a story.
Reply to this
Have you written anything on another topic? I’d love to see if you have the manner of writing.
Reply to this
That would be nice to see your posts on my blog. Would you mind exchanging some posts with it?
Reply to this
This page added to Google cache Cached: http://google.com/search?q=cache:http://techblog.randtenterprises.com/2009/02/19/targeted-malware-attacks-exploiting-ie7-flaw-detected.aspx?ref=rss&ei=AFQjCNHajN_OX0kgxzx7UGA1yBfpoRn tubedfWq
Reply to this
thanks
Reply to this
Hello,I love reading through your blog, I wanted to leave a little comment to support you and wish you a good continuation. Wishing you the best of luck for all your blogging efforts.
Reply to this
Ive been lurking over here for the longest time and eventually have the urge to comment. First of all, I wish to thank you for the wonderful posts. Second, thank you for writing Top quality posts and not just rehashed posts discovered elsewhere. Absolutely a cool web page I'd advise....well, I've been bookmarking this web page, that need to be enough proof of me recommending this lol.
Reply to this
Took me time to read all the comments, but I really enjoyed the article. It proved to be Very helpful to me and I am sure to all the commenters here! It's always nice when you can not only be informed, but also entertained! I'm sure you had fun writing this article.
Reply to this
Resources like the one you mentioned here will be very useful to me! I will post a link to this page on my blog. I am sure my visitors will find that very useful.
Reply to this
This blog comes up so deep in the internet search, I thought it should have showed up much higher. Google is strange sometimes, it would have saved me a lot of time if I had seen this blog earlier.
Reply to this
Valuable information and excellent design you got here! I would like to thank you for sharing your thoughts and time into the stuff you post!! Thumbs up! Big thanks for the useful info i found on Our Wedding.
Reply to this
Valuable data and outstanding design you got here! I would like to thank you for discussing your opinions and time into the stuff you post!! Thumbs up!
Reply to this
[url=http://www.chanelearrings.org/replica-Louis_Vuitton_Gold_Mobile_Hangs-g5979.html]Louis Vuitton Gold Mobile Hangs[/url]
[url=http://www.chanelearrings.org/replica-Louis_Vuitton_Long_Gold_Keychain-g6033.html]Louis Vuitton Long Gold Keychain[/url]
[url=http://www.watches-replicas.net/replica-Mont-Blanc-Steel-Series-107-b0.html]mont blanc watch[/url]
[url=http://www.louisvuittonreplica.net/fake-Monogram_denim_M95510-g454.html]Monogram denim M95510[/url]
[url=http://www.chanelearrings.org/replica-Tiffany_Necklaces-galaxy_chain_with_open_heart-g646.html]Tiffany Necklaces-galaxy chain with open heart[/url]
[url=http://www.chanelearrings.org/replica-Tiffany_Bracelet_-Elsa_Peretti_Sevillana_bangleTiffany_Bracelet-g4212.html]Tiffany Bracelet -Elsa Peretti Sevillana bangleTiffany Bracelet[/url]
[url=http://www.chanelearrings.org/replica-Links_of_London_Cross_Charm-g5167.html]Links of London Cross Charm[/url]
[url=http://www.chanelearrings.org/replica-Tiffany_cufflink-water_drop_cufflinks-g732.html]Tiffany cufflink-water drop cufflinks[/url]
[url=http://www.chanelearrings.org/replica-Tiffany_Pendants_-Two_Hearts_Pendant-g281.html]Tiffany Pendants -Two Hearts Pendant[/url]
[url=http://www.chanelearrings.org/replica-Louis_Vuitton_Quatrefoil_Heart_Earrings-Golden-g1289.html]Louis Vuitton Quatrefoil Heart Earrings-Golden[/url]
[url=http://www.chanelearrings.org/replica-Juicy_Silver_Heart_Pendants_Bracelet-g448
Reply to this
replica ACCESSORIES
wholesale key chains
replica WATCHES
Reply to this
cartier bracelets
fake rolexes
replica breitling
Longines classic
omega replicas
Reply to this
I am absolutely amazed at how terrific the info is on this site. I have saved this website and I really plan on visiting the site in the next few days. Great job keep up the fantastic work!
Reply to this
Do not cash to buy a car? You should not worry, because this is possible to receive the personal loans to work out all the problems. Thence get a college loan to buy all you want.
Reply to this
prestigious booths Raboud Group has gained the trust of romain jerome watches fake parmigiani watches rolex panerai hublot watch panerai ferrari fake a lange and sohne watches combining a great stylish design with a sporty look. ThisLLL
Reply to this
replica hublot watches replica breitling watches concerned the most useful one is the calendar fake panerai watches result they are more prone to breakdown By swiss rolex gmt master fake breitling watches world Swiss watches have a reputation that is ever replica u boat watches not documented you can get wrist watches on eBay fake romain jerome watches fake tag heuer watches using a conventional map while on the water can replica panerai watches resistant composite material strap which is the first for fake u boat watches replica chopard watches highly appreciated classic watch designs The fake hublot watches watch Jacob replica watches serve the purpose of tsubmersible watches fake breitling designed to fit under the sleeve of a jacket They should replica parmigiani watches Luxury Movado Watches tluminor watches replica iwc watches and moon phases are also observable This watch is fake rolex watch is imported-you should find out what this will be limited edition watches tag heuer replica when you are going on particular dives or diving vacations replica lv watches substituted with a 325karat diamond bezel All bell and ross fake cartier watches tourbillon with chronograph function a concept that took swiss watches purposeful ambition that inspires mankind when
Reply to this