Auteur Sujet: [FireEye]On the new Explorer XML zero day  (Lu 3013 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[FireEye]On the new Explorer XML zero day
« le: mai 14, 2019, 22:00:19 »
On the new Explorer XML zero day


 
    See update below!


 


 
   
      Shadowserver
              href="https://www.shadowserver.org/wiki/pmwiki.php/Main/HomePage?logdate=200812"
        target="_blank">is reporting
        on websites serving up a new
        zero day Internet Explorer exploit involving XML (see also

      SecurityFocus 
      and an initial so-far-sketchy 
              href="http://www.microsoft.com/technet/security/advisory/961051.mspx">Microsoft advisory
      ).  For the sake of our
        customers (and potential customers!) I wanted to tentatively
        report that a) indeed this appears to be a real factor in the
        wild by now, and b) the FireEye product does appear to be
        correctly detecting it in at least one case.  I checked around a
        few boxes I have access to and found a VM verified web infection
        event which was initiated from the web server 

    94.102.50.131.   (        style="color: rgb(51,51,51);font-size: 12.0px;line-height: 14.0px;">That
        IP address should be assumed to be armed and dangerous).  Our
        statistical anomaly algorithms picked up on the following piece
        of javascript (this is a screenshot so should be harmless unless
        you retype it:)


 

   

 

 

          style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;">I
      haven't seen this         style="color: rgb(0,0,0);line-height: normal;font-size: 11.0px;font-family: Courier;"><object
        id=xmltarget
        classid="CLSID:88d969c5-f192-11d4-a65f-0040963251e5">
                    style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;white-space: normal;">in
          malicious Javascript recently enough that I can recall it off
          the top of my head - and some grepping on the boxes I checked
          found only this one event like this in the last month.
             "
                            style="font-family: Courier;">88d969c5-f192-11d4-a65f-0040963251e5"                 style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;white-space: normal;">turns
                out to be the class ID for the ActiveX control that implements 

                              style="font-family: Verdana;white-space: normal;">XMLHTTP
                within Microsoft XML Core Services                   style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;">so
                  it seems likely that this is an instance of the new
                  exploit (though I haven't verified that yet)                     style="color: rgb(0,0,0);font-family: Verdana;font-size: 11.0px;line-height: normal;">.
                     There was a vulnerability in this component back in
                    2006 (eg see the Securiteam advisory                    style="color: rgb(0,0,0);font-family: Verdana;font-size: 11.0px;line-height: normal;"> from
                    that time).  If so, it's at least possible that the
                    instructions at that link for disabling that
                    component would also be protective here.  That would
                    be less impactful than not browsing with IE 7.
                     (Again, I stress that I haven't confirmed that
                    speculation - I'm throwing out the possibility in
                    case it's helpful to others in the
  community).

      style="font-family: Verdana;font-size: 11.0px;line-height: normal;"> 

   
              style="color: rgb(51,51,51);font-family: Arial;font-size: 12.0px;line-height: 14.0px;">More
        tomorrow hopefully.

     
 

      style="font-family: Verdana;font-size: 11.0px;line-height: normal;"> 

   
     
        Update:

      style="font-family: Verdana;font-size: 11.0px;line-height: normal;"> 

          style="font-family: Verdana;font-size: 11.0px;line-height: normal;">It
      turned out when we investigated this in detail that it's not
      related to the XML zero-day vulnerability.  We've now seen four of
      these events at various customers with the same starting
      <object> tag with the same classid.  We haven't seen that
      particular form before, and Google does not find other discussions
      of it.  The obfuscated body is polymorphic but when deobfuscated
      reveals a bunch of older browser/plugin exploits.  One of the
      incidents succeeded in infecting the client, and on investigation,
      that turned out to be
          href="http://www.virustotal.com/analisis/36849b53e695b592dccdb878e456e476">this
      fresh packing

          style="font-family: Verdana;font-size: 11.0px;line-height: normal;">
      of the Grum bot.  The destination IP of the exploit server was the
      same in all cases, and it's a known RBN IP address.  The campaign
      appears to be driven by malicious ads.  Thanks to Julia, Atif, and
      Alex for help in investigating, and apologies for any confusion:
      it appears to be a new obfuscation idiom and a new packing that
      was not recognized by almost any AV, but not a new exploit - just
      coincidence that the XMLHTTP classid was used on the same day that
      the new XML exploit was out.  style="font-family: Helvetica;font-size: 12.0px;">

Source: On the new Explorer XML zero day

Tags: