Posts

Continued Activity targeting the Middle East - PART 2

Image
Update 2017-11-15 : Palo Alto's Unit42 released a blog  with additional details about the same activity and they are dubbing the group behind this as "MuddyWater". INTRODUCTION In an earlier blog post , I wrote about a campaign that was targeting the Middle East (Saudi Arabia, Iraq, UAE, etc). The adversary group behind this campaign seem to have been continuing its activity and advancing its techniques. In this blog I will be sharing some additional details about this adversary group and how they are continuing to evolve. They are still using MS Word documents as lures with embedded Macros and PowerShell scripts however, they have been increasing their obfuscation techniques to make detection harder. PART 1 - PANDA WAS HERE. In my previous blog, I mentioned a sample "dollar[.]doc" MD5  a86249a392b394c803ddbd5bbaa0b4bb . While analyzing the sample and looking at some of the strings, one string was interesting " panda was here :) " Using this ...

Knock Knock Knocking on EhDoor (The Curious Case of an EPS file)

Image
INTRODUCTION This all started with the great analysis and blog done by RSA in August 2017 about a phishing wave targeting Russian Banks. This was followed by another great blog by McAfee on the same subject but my focus will be on a specific aspect mentioned in the RSA blog which is the exploit used. “FireEye discovered a malicious docx exploiting a zero day vulnerability in Microsoft’s Encapsulated Postscript (EPS) filter, in the summer of 2015. This EPS exploit was assigned CVE-2015-2545. In March 2017, FireEye observed both nation state and financially motivated actors using EPS zero day exploits assigned as CVE-2017-0261 and CVE-2017-0262, prior to Microsoft disabling EPS rendering in its Office products with an update in April 2017.” PART 1 - ADDITIONAL SAMPLE RELATED TO THE PHISHING CAMPAIGN. One thing I took from the analysis done on the samples from the RSA blog was the name of the EPS file which was “image1.eps”. If you take that and search it, one of the results ha...

Continued Activity targeting the Middle East

Image
This blog will discuss and uncover additional details regarding a recent campaign targeting entities in the Middle East. On Tuesday September 26, 2017 MalwareBytes blogged about a phishing campaign targeting the Middle East, more specifically Saudi Arabia. I started by trying to find the sample that the blog post analyzed and I was able to find it submitted to the great sandboxing site of Hybrid Analysis (Big Shutout to @PayloadSecurity for the great service). The file ( b0a365d0648612dfc33d88183ff7b0f0 ) was named GSB[.]doc which is short for (Government Service Bus) or in Arabic (قناة التكامل الحكومية) as seen below The lure document perpetrating to be from GSB or تكامل Looking at the Macro code within the document, I was able to find that the code doesn't only try to get additional scripts from pastebin but also try to reach to filebin site as well to fetch the same file as shown below after doing some cleanup on the code Moving on, I wanted to t...

Vulnerabilities and Exploits Flying all over in Vancouver

If you want to be a witness to all kinds of new Vulnerabilities and Exploits to major Web Browsers, OS, and Mobile devices, then you should head right away to Vancouver, BC, Canada where the CanSecWest Conference is taking place. The infamous Pwn2Own contest is well underway and is bringing results like no other contest. In the past 2 days vulnerabilities in Microsoft's IE 8 was discovered and exploited by Peter Vreugdenhil a security researcher participating in this contest. Apple's Safari was also exploited mostly to Own iPhone devices. Mozilla's Firefox was not left out of the party. A security researcher that goes by the name of Nils developed the exploit to attack Firefox 3.x. Note that all of those Vulnerabilities and exploits will be reported to Vendors in order to provide sufficient patches and the exploit code will not be available until the vendors patch there products. Nils2Own: 'I want to see security flaws fixed'

The Reason behind Conficker

If you are in the security field, you probably had heard about the Conficker Worm . But for everyone else who is interested in Information Security, or anybody in the IT field, or even anyone who owns a PC, this is a concern. The Conficker Worm was on of the highlights of the first quarter of last year and the end of 2008. You will find the link at the bottom of this post that tells you all about Conficker. This post is to show you the reason behind Conficker and how it came to live. It started in October 23, 2008 when Microsoft reported a Vulnerability in their

Latest Internet Explorer 0-day Vulnerability Demo

Most of you have already heard or know about the latest 0-day vulnerability affecting Microsoft's Internet Explorer. In the video demo below, i show you how to perform the attack on a demo lab network. As always this video is for tutorial and educational purposes only. I am also providing the original advisory from Microsoft and the vulnerability information from Secunia and Security Focus which both are considered to be leaders in providing vulnerability advisories. Microsoft Advisory: http://www.microsoft.com/technet/security/advisory/981374.mspx BID: http://www.securityfocus.com/bid/38615 Secunia ID: http://secunia.com/advisories/38860 For any questions, comments, or recommendations; leave it in the comments section below.