Jump to content

FireEye Malware

Intelligence Lab

Threat research, analysis, and mitigation

17 posts categorized "Vulnerability Research"

The Number of the Beast

Yesterday, we sent out a warning regarding the PDF zero-day we found being exploited in the wild. Adobe has released a security advisory with mitigations. Here are more details about the attack. 

The JavaScript embedded in the crafted PDF is highly obfuscated using string manipulation techniques. Most of the variables in the JavaScript are in Italian. The JavaScript has version checks for various versions of Adobe Reader as shown below and it creates the appropriate shellcode based on the version found.

Continue reading "The Number of the Beast" »

In Turn, It's PDF Time

[Update: February 13, 2013] We have found IE, Java, and Flash zero-days in a row in the past several months, and now it's PDF’s turn. Today, we identified that a PDF zero-day is being exploited in the wild, and we observed successful exploitation on the latest Adobe PDF Reader 9.5.3, 10.1.5, and 11.0.1.

Upon successful exploitation, it will drop two DLLs. The first DLL shows a fake error message and opens a decoy PDF document, which is usually common in targeted attacks. The second DLL in turn drops the callback component, which talks to a remote domain.

Continue reading "In Turn, It's PDF Time" »

Happy New Year from New Java Zero-Day

We observed that a Java security bypass zero-day vulnerability (CVE-2013-0422) has been actively exploited in the wild starting Jan. 2. We have been able to reproduce the attack in-house with the latest Java 7 update (Java 7 update 10) on Windows.

We initially wanted to hold off on posting this blog entry until we received confirmation from Oracle; however, since other researchers are starting to blog on this issue, we have decided to release our summary. We will continue our research and continue to share more information.

Continue reading "Happy New Year from New Java Zero-Day " »

CFR Watering Hole Attack Details

[Updated on December 30, 2012] On December 27, we received reports that the Council on Foreign Relations (CFR) website was compromised and hosting malicious content on or around 2:00 PM EST on Wednesday, December 26. Through our Malware Protection Cloud, we can confirm that the website was compromised at that time, but we can also confirm that the CFR website was also hosting the malicious content as early as Friday, December 21—right before a major U.S. holiday.

Continue reading "CFR Watering Hole Attack Details" »

Looking Forward to Windows 8: A Look Back at Windows Security

With the release of Windows 8 scheduled for October 26, Windows security is on our mind. Windows is one of the most widely used operating systems in the world, making it a lucrative target for exploit developers and malware authors. In previous versions of Windows, many security features were introduced, including ASLR, DEP and pointer encodings. Microsoft utilized software development lifecycle and threat modeling to ensure it was delivering a secure operating system to its users; however, many of previous Windows security exploits were the result of developers overlooking the proper implementation of protocol standards. Supplementing the detailed analysis made available by Microsoft, in this blog post, we share additional analysis of one of these exploits and highlight a short list of additional exploits that were the result of poor security validation.

Microsoft implemented many initiatives focused on developing code that was secure from exploitation of vulnerabilities, but unfortunately, many zero-day vulnerabilities were reported in Windows 2008 and Windows 7.

Let’s dive into the analysis of one zero-day CVE-2011-0654 which was reported on February 14, 2011, for Windows 7 and 2008 servers to understand the factor that seems to have been missed to ensure the safety of Windows.  

Continue reading "Looking Forward to Windows 8: A Look Back at Windows Security" »

Analysis of Malware Page

Target and Delivery Method

Malware Page employs the vulnerability in PDFs and has been seen to be delivered via email. Agenda_Web_(8-24-12).pdf is one of the names this malicious sample uses. Per our logs this sample has been seen to target the aviation defense industry, making this malware a critical limited edition threat. When the malicious PDF file is opened, it infects the victim’s machine and a decoy document is generated. When the decoy PDF file is opened in Acrobat Reader, as shown in Figure 1, the victim finds an invitation to an actual defense industry event.

Image2.jpg

Figure 1. Contents of the decoy PDF file

The purpose of this blog is to share the technical details about this critical limited edition malware.

Continue reading "Analysis of Malware Page" »

Java Zero-Day - First Outbreak

A few days ago I talked about the existence of a new java zero-day flaw (CVE-2012-4681). Soon after the publication of my blog, the white-hats kicked in and there was Proof Of Concept (POC) code ready overnight. At this point, a major outbreak was inevitable. We soon came to know that the master mind behind the Blackhole exploit kit has plans to add this zero-day to his package. This morning we started getting the first indication of a large scale attack. So far we have observed over a dozen domains actively attacking systems with this exploit, and the count is increasing rapidly. After seeing the reliability of this attack, I have no doubt in my mind that within hours the casualties will be in the thousands.

Continue reading "Java Zero-Day - First Outbreak" »

Tracking Email Malware Trojan.MyAgent

At FireEye we have been tracking a particular piece of malware we call Trojan.MyAgent for some time now. The malware is currently using email as its primary vector of propagation. From looking at the data in the FireEye Malware Protection Cloud (MPC), we can see that the malware is currently targeting the following industries:

  • Defense
  • Chemicals
  • Technology
  • Aerospace

Continue reading "Tracking Email Malware Trojan.MyAgent" »

Spear phished by FireEye?

Blogging about crimeware (commodity malware that will infect victims in a purely opportunistic fashion) is an easy thing to do ethically, as the “victim” often times does not add much value to the story. Also, there are so many copies of the malware publicly available that talking about the threat does not compromise your collection source, and in general, we try to avoid “naming names” for the sake of shaming anyone. 

In the case of crimeware, whether a home user or a chemical company gets compromised by a ddos bot, the malware is going to act pretty much the same. For this reason, publicly talking about those types of threats don’t lead you down discussions of, “But now they now know that you know!” 

Continue reading "Spear phished by FireEye?" »

FireEye Advanced Threat Report 2H 2011 Now Available

The new FireEye Advanced Threat Report for the second half of 2011, released today, is not your typical threat report. The threats we cover aren’t the known malware and spam you’ll find published in reports from traditional security vendors. Instead, what you’ll find is insight into advanced threats that have successfully evaded traditional lines of defense, including firewalls, IPS, gateways and antivirus.

Continue reading "FireEye Advanced Threat Report 2H 2011 Now Available" »