FireEye revealed APT Operation DeputyDog against Japanes entities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2013-3893 | Memory Corruption RCE in Microsoft Internet Explorer CVE-2013-3893 is a resource-management (memory corruption) flaw in Microsoft Internet Explorer that can allow remote code execution (CWE-399). It is triggered remotely, typically when a user views attacker-controlled web content in a vulnerable version of Internet Explorer. A successful attacker gains the ability to execute arbitrary code in the context of the current user, potentially compromising the workstation. Organizations still running Internet Explorer, which CISA notes may be end-of-life (EoL) and/or end-of-service (EoS), are affected; specific affected version ranges were not provided in the source data. The flaw was patched in Microsoft's October 2013 Patch Tuesday after being exploited in the wild (Operation DeputyDog, per related reporting), and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-12 with a very high EPSS of 85.9% (100th percentile), indicating active or imminent exploitation. Do: Apply mitigations per Microsoft's vendor instructions and follow applicable BOD 22-01 guidance for cloud services, or discontinue use of Internet Explorer if mitigations are unavailable, per CISA's required action. Verify that affected systems have the October 2013 Patch Tuesday (or later) cumulative Internet Explorer security updates installed, and audit your estate for remaining legacy IE usage. Where IE is still needed for legacy sites, migrate to Microsoft Edge with IE mode and treat in-the-wild exploitation as likely given the KEV listing and 85.9% EPSS. | — | 86% | KEV |
| masstens to hundreds of millions of legacy Windows devices historically capable of running IE; current actively used legacy IE installs unknown but plausibly in… |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | ali.blankchair.com | 2 rt.blankchair.com 2013-09-01 05:02:21 2013-09-01 08:25:24 ali.blankchair.com 2013-09-01 05:02:20 2013-09-01 08:25:22 dll.freshdns.org 20 |
| domain | dll.freshdns.org | ali.blankchair.com 2013-09-01 05:02:20 2013-09-01 08:25:22 dll.freshdns.org 2013-07-01 10:48:56 2013-07-09 05:00:03 Campaign such as th |
| domain | ea.blankchair.com | icious domains identified are : Domain First Seen Last Seen ea.blankchair.com 2013-09-01 05:02:22 2013-09-01 08:25:22 rt.blankchair.com 2 |
| ipv4 | 103.17.117.90 | 28.102 4d257e569539973ab0bbafee8fb87582 2013-08-19 13:21:58 103.17.117.90 dbdb1032d7bb4757d6011fb1d077856c 2013-08-19 13:21:59 110.45 |
| ipv4 | 110.45.158.5 | 117.90 dbdb1032d7bb4757d6011fb1d077856c 2013-08-19 13:21:59 110.45.158.5 645e29b7c6319295ae8b13ce8575dc1d 2013-08-19 13:21:59 103.17 |
| ipv4 | 180.150.228.102 | chair [ . ] com – the domain that we see was pointed to the 180.150.228.102 IP, which is the callback associated with sample 58dc05118e |
| md5 | 4d257e569539973ab0bbafee8fb87582 | ef8b11dcb5f5c596ab772fd 2013-08-19 13:21:58 180.150.228.102 4d257e569539973ab0bbafee8fb87582 2013-08-19 13:21:58 103.17.117.90 dbdb1032d7bb4757d6011fb1d |
| md5 | 58dc05118ef8b11dcb5f5c596ab772fd | 50.228.102 IP, which is the callback associated with sample 58dc05118ef8b11dcb5f5c596ab772fd, and has been already correlated back to the attack leverag |
| md5 | 645e29b7c6319295ae8b13ce8575dc1d | 32d7bb4757d6011fb1d077856c 2013-08-19 13:21:59 110.45.158.5 645e29b7c6319295ae8b13ce8575dc1d 2013-08-19 13:21:59 103.17.117.90 e9c73997694a897d3c6aadb26 |
| md5 | dbdb1032d7bb4757d6011fb1d077856c | 69539973ab0bbafee8fb87582 2013-08-19 13:21:58 103.17.117.90 dbdb1032d7bb4757d6011fb1d077856c 2013-08-19 13:21:59 110.45.158.5 645e29b7c6319295ae8b13ce85 |
| md5 | e9c73997694a897d3c6aadb26ed34797 | 7c6319295ae8b13ce8575dc1d 2013-08-19 13:21:59 103.17.117.90 e9c73997694a897d3c6aadb26ed34797 2013-04-13 13:42:45 110.45.158.5 The malicious domains iden |
Full article619 words · extracted from securityaffairs.com · click to collapse
Security experts at FireEye discovered the Operation DeputyDog against Japanese entities that exploits Zero-Day (CVE-2013-3893) recently announced by Microsoft.
FireEye announced the discovery of the cyberespionage Operation DeputyDog leveraging the recently announced zero-day CVE-2013-3893. FireEye and Kaspersky are the companies most active in the analysis of large espionage campaign that governments and hackers are conducting against strategic targets.
According the analysis based on FireEye Dynamic Threat Intelligence cluster the Operation DeputyDog began as early as August 19, 2013 targeting Japanese organizations. Security experts found that attackers have used the same command and control infrastructure of the attack on Bit9 firm.
Bit9 experts discovered that hackers penetrated their network infecting machine with two variants of the HiKit rootkit.
“One of these Hitkit samples connected to a command and control server at downloadmp3server[.]servemp3[.]com that resolved to 66.153.86.14. This same IP address also hosted www[.]yahooeast[.]net, a known malicious domain, between March 6, 2012 and April 22, 2012. The domain yahooeast[.]net was registered to [email protected]. This email address was also used to register blankchair[.]com – the domain that we see was pointed to the 180.150.228.102 IP, which is the callback associated with sample 58dc05118ef8b11dcb5f5c596ab772fd, and has been already correlated back to the attack leveraging the CVE-2013-3893 zero-day vulnerability.”
Just a couple of days ago, on September 17, 2013 Microsoft announced a new zero-day vulnerability in Internet Explorer products that was being exploited in targeted attacks.
FireEye investigated on the attacks revealing that they targeted organizations in Japan, according evidences collected behind the Operation DeputyDog there is the same threat actor that compromised Bit9 in February 2013, when during the hack were stolen digital certificates used later in further attacks to sign malware. The payload used in these attacks on August 23th 2013 against entities in Japan was hosted on a server in Hong Kong with IP address equal to 210.176.3.130. Despite the payload is named img20130823.jpg in reality it is an executable, once run it writes a dll named “28542CC0.dll” in the following path:
C:\Documents and Settings\All Users\Application Data\28542CC0.dll
To be able to execute the malware on every machine restarts the malicious agent also adds this registry key:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\28542CC0 rundll32.exe “C:\Documents and Settings\All Users\Application Data\28542CC0.dll”,Launch
The malware connects to a host in South Korea (180.150.228.102), it is curious that callback traffic is not encrypted HTTP over port 443. The FireEye security experts identified the signature for the attacks that allowed the detection of at least 5 samples that were compiled on 2013-08-19, within 1 second of each other.
| MD5 | Compile Time (UTC) | C2 Server |
| 58dc05118ef8b11dcb5f5c596ab772fd | 2013-08-19 13:21:58 | 180.150.228.102 |
| 4d257e569539973ab0bbafee8fb87582 | 2013-08-19 13:21:58 | 103.17.117.90 |
| dbdb1032d7bb4757d6011fb1d077856c | 2013-08-19 13:21:59 | 110.45.158.5 |
| 645e29b7c6319295ae8b13ce8575dc1d | 2013-08-19 13:21:59 | 103.17.117.90 |
| e9c73997694a897d3c6aadb26ed34797 | 2013-04-13 13:42:45 | 110.45.158.5 |
The malicious domains identified are:
| Domain | First Seen | Last Seen |
| ea.blankchair.com | 2013-09-01 05:02:22 | 2013-09-01 08:25:22 |
| rt.blankchair.com | 2013-09-01 05:02:21 | 2013-09-01 08:25:24 |
| ali.blankchair.com | 2013-09-01 05:02:20 | 2013-09-01 08:25:22 |
| dll.freshdns.org | 2013-07-01 10:48:56 | 2013-07-09 05:00:03 |
Campaign such as the Operation DeputyDog are the demonstration that groups of persistent collectors are very active and use sophisticated techniques for their attacks. The hackers exploited the knowledge of a zero-day during last attacks, circumstance that lets me think of the responsibility of state-sponsored hackers. Governments are primary entities that exploit zero-day flaws during their attack, cybercrime ecosystem in fact is more oriented in the sale of these exploits instead to use it for illegal activities. If you are interested to go deep in the technical analysis of the ATP read the following post published by FireEye.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – FireEye, Operation DeputyDog, cyberespionage)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/17975/hacking/fireeye-operation-deputydog-japan.html