Showing posts with label Macros. Show all posts
Showing posts with label Macros. Show all posts

Wednesday, 8 July 2015

Office Component Allows Attacker's Code Without Executing Macros


A researcher warns Office users a feature allowing attackers to execute malicious code through documents, even if macros are turned off and the part is not off. Every Windows version of Microsoft Office contains a feature that makes it possible to embed content in documents.

These include the executable content, such as .exe and JavaScript files, so let investigator Kevin Beaumont on the Full Disclosure mailing list know. OLE Packager, as the feature is called, since the early 1990s in the Microsoft software is present. The feauture, which allows the embedding of content, was introduced in Windows 3.1 and was supported until Windows XP. All versions of Office support the feature yet. To prevent any abuse of the feature made ​​Microsoft uses a list of risky file types.

Once a risky file type to a document is added to the list view shows a warning to the user. This warning can be ignored, but users can at least see that the document contains risky content. According to Beaumont the static list is not, however, up-to-date. For example, PowerShell and other executable files not recognized and therefore users get no warning. Thus, it is possible to carry out through the opening of Office files code on the computer. It does not stand out or macros off, or that of High Security templates are used.

Solution

Microsoft was informed in March of this year about the problem and was told that attackers were experimenting with the feature. To not know what is exactly the attackers and attacks Beaumont late. However, Microsoft then would have asked him not to publish information about the issue. Eventually told the researcher that it is and the problem is still not resolved to a feature of Office. For Windows users, Microsoft EMET installed, a free tool for Windows with secure, to assume control for Excel, Word and PowerPoint that prevents the feature can be implemented. However, this also prevents legitimate use of the feature

Thursday, 25 December 2014

Dridex Malware - "Christmas Offers Conatins Macro Malware"


Christmas Offers.Docx

Spammers have Christmas as a chance to send e-mails that seem to contain a Christmas special initially look, however truly unfold malware. The e-mails going around currently feature a Word document referred to as "Christmas Offerings" hooked up. Once opened, attempt the macros within the document to transfer a malicious executable file.

The authors have created several macros in fact

Because of the protection risks interference Microsoft office standard macros and users also get to check a security warning that the macros are disabled. within the same warning might opt for, however, users need to to show the content of the document. The user selects this, then the Dridex Trojan is downloaded to the pc. this can be a Trojan specifically designed to steal cash from on-line bank accounts, according to anti-virus company Malwarebytes.

VBA code

Virustotal Report:- Christmas Offers.Doc

Virustotal Analysis Report of Christmas Offers.Docx

MD5: 9d0b2db07a5c5a903e0d599c8fcc63ca


Virustotal Report of Downloaded Exe:

Virustotal Analysis Report of Dowloaded Exe

MD5: 09e21abb85829788cab67d112d1b7c95

Macro Example: