Showing posts with label Microsoft Office. Show all posts
Showing posts with label Microsoft Office. Show all posts

Wednesday, 11 November 2015

Microsoft Patches 53 Vulnerabilities In Windows, IE And Office


During the November Patch Tuesday, Microsoft has 53 vulnerabilities in Windows, Internet Explorer, Microsoft Edge, Office and several other products poem, including four zero-day vulnerabilities. The total contribution amounts to four twelve security updates, which are labeled as critical.

Critical updates address vulnerabilities that could allow an attacker to run arbitrary code on the computer can perform, without much user interaction. These four are updates for Internet Explorer, Edge and Microsoft Windows. There are also updates for Office, Lync, Skype for Business and .NET Framework appeared. Most leaks are fixed in Internet Explorer, namely 25.

In the case of the four zero-day vulnerabilities were those found in Windows and Office. It involved vulnerabilities that had already been announced for the release of the patches. According to Microsoft, there are no indications that the vulnerability for the appearance of the updates are attacked. An overview of all published Security Bulletins on this page to find. Updating via the Automatic Update feature, which is enabled on most Windows computers.

Saturday, 10 October 2015

From Critical Vulnerabilities In Adobe Reader And Acrobat Seal


Adobe will coming Tuesday, October 13th security updates for critical vulnerabilities in Adobe Reader and Acrobat release, but users will get this time not advised to install the updates within 72 hours. This is clear from the notice which Adobe has released.

Security updates have in fact been given a "priority 2". This means that the corrected vulnerabilities, which have been labeled as critical, not be attacked active and there are no attacks are expected shortly. In this case, Adobe advises users and administrators to quickly install the security updates, with 30 days as exemplified. In the case of updates with "priority one" install the updates is presented within 72 hours.

Through Critical vulnerabilities could allow an attacker at worst malicious code on the system without users having this through. Opening a malicious PDF document is sufficient in this case. Were vulnerabilities in Adobe Reader often used in the past to infect computers with malware, the last time this according to statistics from Trend Micro and Microsoft (pdf) is still hardly the case.

Wednesday, 9 September 2015

Microsoft Office: Documents Install Backdoor Through Recent Office Leak



A recent vulnerability in Microsoft Office that in April was patched is already several weeks actively attacked and used to install a backdoor on Windows computers. A problem because many organizations install security updates for Microsoft Office or wait very long time here.

By opening a malicious document, an attacker could then install malware on the computer. A tactic that has been successfully applied. Last year made ​​the British anti-virus firm Sophos study (pdf) to the vulnerabilities that attackers use to this kind of attack. Two leaks, one from 2010 and one from 2012, was attacked by most of the malicious documents. Also from other surveys show that the vulnerability in 2012 the favorite target of attackers.

Although there is an update to the now attacked Office leak for about five months is available, the question is how many organizations have installed. Even before the patch Microsoft released the vulnerability was attacked. Early August saw Sophos, however, pass by a series of papers that try to take advantage of the leak. The documents have subjects like "WUPOS_update.doc", "ammendment.doc", "Information 2.doc" and "Anti-Money Laude Ring & Suspicious cases.doc".

In case the files are opened on an unpatched machine, the code in the document called Uwarrior install a backdoor on the computer. This allows the attackers full control over the machine. To prevent infection, managers and users are advised to patch Office and not to open unexpected or unsolicited documents. Last week warned IBM all e-mail attachments to make a comeback as an attack vector.

Saturday, 18 July 2015

Zero-Day Vulnerability In Microsoft Office Used For Cyber-Espionage


Last Tuesday, Microsoft patched a zero-day vulnerability in Office, which recently has been actively used by a group engaged in cyber espionage. The group sent at least one RTF document on the nuclear negotiations with Iran. The document, which was discovered in Georgia, contained an exploit for a critical vulnerability in Microsoft Office 2013 Service Pack 1 and earlier versions of Office.

Once users opened the paper exploits document was replaced by a genuine document with information on the nuclear negotiations. In the background, however, was installed a backdoor that attackers had full control over the computer, says security firm iSIGHT Partners . According to the company, the group behind the attacks also associated with a recently patched zero-day vulnerability in Java that was also used in targeted attacks.

The group would in April two zero-day vulnerabilities in Flash Player and Windows have used and the recently unveiled Flash exploits which was available to the Italian Hacking Team. The group would have to cater for the collection of military and diplomatic intelligence, although telecoms and defense companies have been targeted. The Office leak that the group is used patched by MS15-070 .

Wednesday, 15 July 2015

Microsoft Patches 59 Vulnerabilities, Of Which 7 Zero Days



Microsoft Patch Tuesday during the July 59 vulnerabilities in Windows, Internet Explorer, Office and SQL Server patched, 7 of zero days. It is in this case for vulnerabilities that were already known or were attacked before the relevant Microsoft security update was available.

Three of the zero-day vulnerabilities in Internet Explorer, Office and Windows were actively attacked, Microsoft said. Two of these vulnerabilities in IE and Windows, were coming from the Italian company hacked Hacking Team. This means that Hacking Team possessed far as is known about five zero-day vulnerabilities. In addition to IE and Windows, the company had also provided with three unknown vulnerabilities in Adobe Flash Player. The remaining four zero-day vulnerabilities that Microsoft patched this month found in IE and were already made ​​public, but according to the software giant does not actively attacked.

Updates

In total there are 14 security updates. Thus it belongs patch round both the number patches as corrected vulnerabilities into one of the toughest rounds patch from Microsoft ever. Four updates, MS15-065 , MS15-066 , MS15-067 and MS15-068 , have the highest priority and are labeled by Microsoft as critical. Through these vulnerabilities, an attacker can take over the underlying system. These include a vulnerability in the Remote Desktop Protocol (RDP). RDP is not enabled by default, but if that is the case an attacker by sending a few packets take over the system.

Three other updates are not labeled as critical, but let an attacker or run arbitrary code on a computer. It is MS15-058 for SQL Server MS15-069 for Windows and MS15-070 for Office. Microsoft regards this update as "important" because an attacker needs to do more effort before code execution is possible. The other security bulletins this month fix vulnerabilities that an attacker can increase his privileges on the computer. These include to the zero-day flaw in Windows which was discovered by Hacking Team. In these vulnerabilities, an attacker must already have access to the system before use can be made.

The updates can be downloaded via Windows Update and will be automatically installed on most computers. An overview of all bulletins on this page to find.

Monday, 22 June 2015

US Data Leaks School Children In PowerPoint Presentation



An American school has the private data of preschoolers and schoolchildren leaked into a PowerPoint presentation. During the presentation, which was given by the CTO of the school in 2011, were on a slide to see the pictures of sixteen toddlers, as well as their names and phone numbers.

On another slide listing the names, student numbers and reading scores of 145 "fourth-graders" (similar to group 6, children 9-10 years old) are shown. The presentation was later shown at a different location and ended up on a federal government website. Once an older school in March this year had warned the presentation was removed. In April followed a letter of apology to all parents to, as is now known, according to the Washington Post .

In the letter, the school that the PowerPoint presentation against the rules was not monitored. The chief technology officer, said at one of the affected schools that they did not know the details of real students originated. In addition, the CTO claims not know the organization that the presentations had kept the PowerPoint file uploaded to a website of the National Institute of Standards and Technology (NIST).

Friday, 19 June 2015

PowerPoint Leak Used To Spread Malware


Vulnerability in PowerPoint, which was patched by Microsoft last year is now being actively used to infect activists in Tibet and Hong Kong with malware. The attacks are part of a larger campaign that is taking place for years. Remarkably, however, the use of PowerPoint leak.

Previously used the attackers vulnerabilities in Microsoft Office respectively in 2010 and 2012. The use of the PowerPoint leak would for the first time in two years the trend. For the dissemination of the PowerPoint files as well as e-mail attachments using links to Google Drive. To warn activists against the risk of email attachments campaign "was Detach from Attachments "starts. It is just recommended to use cloud storage for sharing files, such as Google Drive.


The fact that the attackers now use Google Drive, according to the investigators as possibly an indication that the attackers adapt accordingly. When users open the PowerPoint updates from Microsoft are not installed and the presentation they can with a remote access Trojan (RAT) become infected. The malware would be recognized by a few virus scanners.

In total, the researchers saw the Canadian CitizenLab five campaigns where the PowerPoint leak was deployed. To let users do not suspect they get to see a real presentation, while the malware is installed in the background. "The recycled content, low detection scanners and that users do not know that these files are malicious, ensure that these attacks are worrying," the researchers said.

Friday, 29 May 2015

Malignant Macro Virus Bypasses Via MHTML Format



Cyber criminals have used a remarkable file to malicious macros invisible for virus scanners, as several researchers have discovered. The use of macros in Office documents has become a popular tactic to spread malware.

Macros are disabled by default in Office, but when users enable the macro can download and install malware. Recently discovered researcher Bart Blaze a spam campaign where there is a doc file with malicious macros added. In reality it turned out to be a Word MHTML file. According to researchers at security firm Trustwave beat the criminals after making the malicious macro as an MHTML file, to which then rename it to .doc or .xls. As a result the file will be opened by Microsoft Office.

When the spam campaign was detected showed that most virus scanners that are not detected. According to investigators, the criminals have malicious macros intentionally saved as MHTML file, to circumvent virus. An analysis of the MHTML file shows that the part of the evil macro via base64 encoded. In case users open the attachment and run the macro is a Trojan horse installed that is specifically designed to steal money from online bank accounts. Users also are advised to Microsoft Office can be configured to all macros are blocked.

Thursday, 14 May 2015

Cisco Raises The Alarm For Advancing Macro-Malware


In half a year, the number of attacks doubled through macro-malware, network giant Cisco reason to sound the alarm. The malware is distributed via e-mail attachments that contain Word documents. Once the document is opened, the user is asked whether he wants to enable macros, because Microsoft has it turned off by default for security reasons.

According to Tim Gurganus Cisco, many people forget and turn the threat of macros then, so the malicious code in the document to download and install malware. A successful approach, as evidenced by the increase in the number of e-mail attacks macro-malware is used. The problem is compounded because most email filters and business office documents and not block the malicious macro code geobfusceerd and is very difficult to detect.

The first malicious macros were still out of 150 lines of code, which have now been there in 1500. The makers have all kinds of measures taken to avoid detection and the tactics in the field of social engineering refined. Thus allowed to open a blank page after the first copies, which could alert users that something was wrong. Since early this year "distraction Documents" displayed while in the background the infection takes place. Consequently, users will not suspect that it is malware.

It also appears that the attackers regularly hacked legitimate websites or cloud services like Dropbox, Google Drive or Pastebin.com use to host the malware. The big advantage is that the domains do not stand out in traffic and will not be blocked soon. "Macro-malware is also a good example of malware makers who respond severely becoming security measures, such as blocking zip files containing .exe files. Attackers continue to adapt their tactics, techniques and procedures," said Gurganus.

Thursday, 30 April 2015

Microsoft Provides Alarm About Macro-Malware


To perform asking Internet users if they macros in Office documents so that their computer is infected with malware is a very successful method for cyber criminals, as the past few months more than half a million computers were infected in this way.

The malware is distributed via e-mails with subjects about bills, taxes, delivery confirmations, CVs and donation confirmations. Topics according to Microsoft, users can easily mislead to open the email and attachment without piggybacked hereby thinking. Once the macro is executed will download a file which then downloads a Trojan downloader. This downloader installs additional malware on the system. The software giant sets raises the question of how this form of social engineering can be combated.

In the case of enterprises, system administrators can take various measures. Most macro malware namely located in the .doc format used in Office 2007 and earlier. Administrators can set up via the Trust Center of Office that documents from earlier Office versions are not loaded. In addition, the operation of macros in Office can be configured , for example, to allow only digitally signed macros or block all macros.

Wednesday, 15 April 2015

RTF Most Popular File Type In Targeted Attacks


Attackers who use through targeted attacks on organizations trying to break into the most RTF documents, claims the Japanese anti-virus company Trend Micro . E-mail attachments that were used in targeted attacks last year was 24% of the cases to an RTF document.

Also DOC documents with 22% a popular file type. According to Trend Micro to explain the popularity of both file types because many organizations working with Microsoft Word. PDF documents are contrary despite the dominance of Adobe Reader hardly used in targeted attacks. Only 2% of the attacks took place via a PDF attachment.

Although last year zero-day attacks took place where attackers used a vulnerability in PowerPoint for which no update was available, it appears that simply avoid most targeted attacks. In many cases use is being made from vulnerabilities that are years old. A known vulnerability CVE-2012-0158. This is a flaw in Word that three years ago was patched. In 10% of the targeted attacks an exploit for this vulnerability was used.

Tuesday, 24 March 2015

Macro Malware Infected Computer By Closing Document


Researchers have discovered a new macro malware that infects your computer only if the document is closed, to circumvent detection. The malware looks to the presence of certain sandboxes like Sandboxie sandbox and Anubis. Macros allow users to automate various tasks and were used years back on a large scale by malware. Because of the security risks, Microsoft decided therefore to block macros by default in Office.

A year ago, appeared more and more .doc and .xls documents containing macros were hidden. The documents users were summoned to enable macros. Once the user enables the macro is the background example, it downloaded and installed malware. At least, that is the expected behavior.

A new variant of the Dridex malware downloads the malware until the user closes the document. According to security firm Proofpoint hope to bypass the malware creators this virus scanners and intrusion detection systems that monitor when opening documents loading malware. For this type of behavior to prevent their detection systems have security sandboxes and adapted to "wait" longer any malicious activity.

"The possibility of malicious macros to perform as the document is closed increases the infection window and forces a detection sandbox to monitor longer and possibly miss the infection. How long sandbox also wait, the infection will not occur, and if the sandbox closes or stops without closing the document, the infection is missed as a whole, " said the researchers from Proofpoint.

Sandbox

Also security PhishMe warns of a variant of Dridex that spreads via macros. This variant looks specifically at the presence of certain sandboxes like Sandboxie sandbox and Anubis. In case these sandboxes are detected, the computer will not be infected. Is the attack or successful, then download the macro Dridex banking Trojan on the computer. This malware is specially designed to steal money from online bank accounts.

Tuesday, 10 March 2015

Attack With Malicious Macros In XML Files


Cyber ​​criminals use to spread again some time macros in documents to malware, but now there are also attacks observed with XML files were deployed. Macros allow users to automate various tasks and were used years back on a large scale by malware. Because of the security risks, Microsoft decided therefore to block macros by default in Office.

A year ago, appeared more and more .doc and .xls documents containing macros were hidden. The documents users were summoned to enable macros. Once the user the macro switch is downloaded and installed malware instance in the background. One tactic that seems to be successful, because the beginning of this year, Microsoft already gave a warning off for macro malware. Now warns security firm Trustwave for a new attack in which malicious macros are used via XML files.

XML stands for Extensible Markup Language and XML-based formats have become the standard for various office tools, including Microsoft Office. When a user loads the XML file opens Office and will appear again indicating that macros must be enabled. After switching a malicious script is executed that downloads and installs a Trojan horse. It is the Dridex banking Trojan, malware specifically designed to steal money from online bank accounts. The Internet Storm Center (ISC) gives organizations advice how this kind of XML files can be filtered.

Thursday, 25 December 2014

Dridex Malware - "Christmas Offers Conatins Macro Malware"


Christmas Offers.Docx

Spammers have Christmas as a chance to send e-mails that seem to contain a Christmas special initially look, however truly unfold malware. The e-mails going around currently feature a Word document referred to as "Christmas Offerings" hooked up. Once opened, attempt the macros within the document to transfer a malicious executable file.

The authors have created several macros in fact

Because of the protection risks interference Microsoft office standard macros and users also get to check a security warning that the macros are disabled. within the same warning might opt for, however, users need to to show the content of the document. The user selects this, then the Dridex Trojan is downloaded to the pc. this can be a Trojan specifically designed to steal cash from on-line bank accounts, according to anti-virus company Malwarebytes.

VBA code

Virustotal Report:- Christmas Offers.Doc

Virustotal Analysis Report of Christmas Offers.Docx

MD5: 9d0b2db07a5c5a903e0d599c8fcc63ca


Virustotal Report of Downloaded Exe:

Virustotal Analysis Report of Dowloaded Exe

MD5: 09e21abb85829788cab67d112d1b7c95

Macro Example: