href="/content/dam/legacy/blog/2012/11/6a00d835018afd53ef0105365acadc970c-500wi.png">
src="https://www.fireeye.com/content/dam/legacy/blog/2012/11/6a00d835018afd53ef0105365acadc970c-500wi.png"
class="at-xid-6a00d835018afd53ef0105365acadc970c landscape-med" alt="Picture 289" />
style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;">I
haven't seen this style="color: rgb(0,0,0);line-height: normal;font-size: 11.0px;font-family: Courier;"><object
id=xmltarget
classid="CLSID:88d969c5-f192-11d4-a65f-0040963251e5">
style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;white-space: normal;">in
malicious Javascript recently enough that I can recall it off
the top of my head - and some grepping on the boxes I checked
found only this one event like this in the last month.
"
style="font-family: Courier;">88d969c5-f192-11d4-a65f-0040963251e5" style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;white-space: normal;">turns
out to be the class ID for the ActiveX control that implements
style="font-family: Verdana;white-space: normal;">XMLHTTP
within Microsoft XML Core Services style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;">so
it seems likely that this is an instance of the new
exploit (though I haven't verified that yet) style="color: rgb(0,0,0);font-family: Verdana;font-size: 11.0px;line-height: normal;">.
There was a vulnerability in this component back in
2006 (eg see the Securiteam advisory style="color: rgb(0,0,0);font-family: Verdana;font-size: 11.0px;line-height: normal;"> from
that time). If so, it's at least possible that the
instructions at that link for disabling that
component would also be protective here. That would
be less impactful than not browsing with IE 7.
(Again, I stress that I haven't confirmed that
speculation - I'm throwing out the possibility in
case it's helpful to others in the
community).
style="font-family: Verdana;font-size: 11.0px;line-height: normal;">
style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;">More
tomorrow hopefully.
style="font-family: Verdana;font-size: 11.0px;line-height: normal;">
Update:
style="font-family: Verdana;font-size: 11.0px;line-height: normal;">
style="font-family: Verdana;font-size: 11.0px;line-height: normal;">It
turned out when we investigated this in detail that it's not
related to the XML zero-day vulnerability. We've now seen four of
these events at various customers with the same starting
<object> tag with the same classid. We haven't seen that
particular form before, and Google does not find other discussions
of it. The obfuscated body is polymorphic but when deobfuscated
reveals a bunch of older browser/plugin exploits. One of the
incidents succeeded in infecting the client, and on investigation,
that turned out to be
href="http://www.virustotal.com/analisis/36849b53e695b592dccdb878e456e476">this
fresh packing
style="font-family: Verdana;font-size: 11.0px;line-height: normal;">
of the Grum bot. The destination IP of the exploit server was the
same in all cases, and it's a known RBN IP address. The campaign
appears to be driven by malicious ads. Thanks to Julia, Atif, and
Alex for help in investigating, and apologies for any confusion:
it appears to be a new obfuscation idiom and a new packing that
was not recognized by almost any AV, but not a new exploit - just
coincidence that the XMLHTTP classid was used on the same day that
the new XML exploit was out.
style="font-family: Helvetica;font-size: 12.0px;">