ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Japan Quake Spam leads to Malware Part 3

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2007-5659
Buffer Overflow in Adobe Acrobat and Reader via Malicious PDF JavaScript

Adobe Acrobat and Reader contain a buffer overflow (CWE-119) in their handling of arguments passed to JavaScript methods when rendering PDF files. An attacker triggers the flaw by convincing a user to open a crafted PDF whose embedded JavaScript calls methods with overly long arguments, and no user privileges beyond viewing the file are required. Successful exploitation allows a remote attacker to execute arbitrary code in the context of the user running Acrobat or Reader. Anyone running the affected Acrobat or Reader versions (specific version ranges are not provided in the source data) is affected, with Adobe Reader historically being one of the most widely deployed desktop applications. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-06-08, confirming exploitation in the wild, and EPSS assigns a 94% probability of exploitation within 30 days (100th percentile); no public proof-of-concept is known and ransomware use is unknown.

Do: Apply updates per vendor instructions by upgrading Acrobat and Reader to the patched releases Adobe made available for your version line, and audit the estate for legacy, unpatched Acrobat/Reader installs given the 2022 KEV listing. As an interim mitigation, disable or restrict JavaScript in the Acrobat/Reader preferences and treat PDFs from untrusted sources (email attachments, drive-by download sites, exploit-kit delivery channels) with caution.

94% KEV
  • Adobe Acrobat
  • Adobe Reader
masshundreds of millions of users/installations historically (Adobe Reader/Acrobat is among the most widely deployed desktop PDF viewers); current unpatched…
CVE-2008-2992
Adobe Acrobat and Reader JavaScript Input Validation Flaw Enables Remote Code Execution

Adobe Acrobat and Reader contain an input validation flaw (CWE-119, memory corruption) in a JavaScript method — historically the util.printf() JavaScript function — that fails to safely handle crafted arguments. An attacker triggers the flaw by getting a user to open a specially crafted PDF containing malicious JavaScript, which can corrupt memory and allow code execution on the victim's machine. Successful exploitation yields remote code execution with the privileges of the logged-in user, typically used to deliver malware; the related headlines indicate this flaw was folded into exploit kits and spam-driven malware campaigns of the era. Anyone running a vulnerable version of Adobe Acrobat or Reader (specific version ranges were not provided in the source data) with PDF JavaScript enabled is affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2022-03-03 with known ransomware use, and EPSS assigns it a 98.5% probability of exploitation within 30 days.

Do: Apply updated versions of Acrobat and Reader per Adobe's instructions, as required by the CISA KEV listing. As an interim mitigation, disable or restrict JavaScript in Acrobat/Reader preferences (a JavaScript blocklist/allowlist approach, consistent with Adobe's JavaScript Blocklist Framework), and caution users against opening unsolicited PDFs, since exploitation has occurred via exploit kits, spam campaigns, and ransomware delivery. Check endpoints for unpatched Acrobat/Reader installs and confirm remediation against the CISA KEV deadline.

98% KEV ransomware
  • Adobe Acrobat
  • Adobe Reader
massHundreds of millions of desktop users (an estimate
CVE-2009-0927
Stack-Based Buffer Overflow in Adobe Reader and Acrobat Enables Remote Code Execution

CVE-2009-0927 is a stack-based buffer overflow (improper input validation, CWE-20) in Adobe Reader and Adobe Acrobat that allows remote attackers to execute arbitrary code on the victim's system. The flaw is triggered when the PDF handling code in these products processes malicious input, typically via a specially crafted PDF document delivered through email, the web, or exploit kits. Successful exploitation gives an attacker the ability to run arbitrary code, generally with the privileges of the user running the PDF application. Any user or endpoint running an affected version of Adobe Reader or Acrobat is exposed, and given the near-universal deployment of these PDF tools the potential population is very large. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25) with a required action to apply vendor updates, and EPSS assigns a 96.6% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Apply updates per vendor instructions: upgrade all affected Adobe Reader and Acrobat installations to a patched release as required by the CISA KEV listing. As an interim mitigation, disable or restrict JavaScript in PDF files (the Acrobat JavaScript blocklist framework introduced around this period addresses this vector) and block PDFs from untrusted sources. Inventory endpoints for outdated Reader/Acrobat versions, prioritizing systems that open PDFs from email and the web.

97% KEV
  • Adobe Reader and Adobe Acrobat
masshundreds of millions of users (Adobe Reader was the dominant PDF viewer on desktops during the exploitation period)
CVE-2009-4324
Use-After-Free RCE in Adobe Acrobat and Reader via Crafted PDF Files

CVE-2009-4324 is a use-after-free vulnerability in Adobe Acrobat and Adobe Reader in which a crafted PDF, typically using embedded JavaScript to invoke the media.newPlayer() multimedia API, frees an object that the program then reuses, corrupting memory. The flaw is triggered simply by opening the malicious PDF, so delivery as an email attachment or web download is enough, and successful exploitation gives an attacker arbitrary code execution with the rights of the logged-in user. Anyone running Acrobat or Reader versions current at the December 2009 disclosure was affected, which effectively meant the very large install base of the then-dominant PDF viewer, with observed attacks focused on Windows. The bug was exploited in the wild around the time of disclosure, with contemporaneous write-ups linking PDF-borne malware to Japan-earthquake-themed spam lures, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-06-08 (ransomware use: unknown). No standalone public proof-of-concept is catalogued, but EPSS ranks it in the 100th percentile with an approximately 82% probability of exploitation within 30 days, so defenders should treat it as actively exploited.

Do: Upgrade Acrobat and Reader to the fixed release in Adobe's January 2010 security update (APSB10-02), per the KEV required action; the versions vulnerable at disclosure are long past end-of-life, so any current deployment is unsupported and should be migrated. As interim mitigation, block or strip JavaScript and multimedia actions in PDFs (for example via Adobe's JavaScript blocklist framework or gateway-level PDF sanitization) and treat unsolicited PDF attachments as untrusted. Hunt on legacy Windows hosts for signs of PDF-borne code execution following receipt of themed spam or unexpected PDF attachments.

82% KEV
  • Adobe Acrobat
  • Adobe Reader
massHundreds of millions of users at the time of disclosure (Adobe Reader's install base); residual unpatched legacy installs today likely in the hundreds of…
Full article597 words · extracted from securelist.com · click to collapse

Last week, we published a blog post regarding the ongoing spam campaign using the recent earthquake in Japan to infect users. This is a follow up blog describing the exploits used.

According to our analysis, it seems that the malicious links from the spam emails lead to websites hosting the Incognito Exploit Kit.

Here is an interesting picture from the servers hosting the exploit kit:

You can see below another example from the spam campaign, this time pretending to be an email from Twitter:

The email disguises itself as a “Twitter Support Message” pretending that you have 6 unread messages from Twitter.

It’s also advertising a VIDEO: Inside the Fukushima’s exclusion zone.

Once visited, the embedded link redirects the end users to the same sort of malicious web sites that we covered last week. Let’s have a closer look regarding the exploits used to install the malicious payload, variants of the Trojan-Downloader.Win32.Codecpack.

We are actively monitoring the malicious pages. In the past 40 hours, the malicious domains hosting the exploits have been changed eight times. They are still trying to infect users.

As a follow up of the exploit page mentioned last week, once decrypted, you get more exploits being used to infect users:

Java Deployment Toolkit: CVE-2010-0886 – April 2010

Java Deployment Toolkit Performs Insufficient Validation of Parameters leading to remote code execution.

Help Center URL Validation Vulnerability: CVE-2010-1885 – June 2010

An iframe to this exploit is created, and you can see that there is an encoded parameter (mostly blurred on the capture above). Once decoded, you get the following code:

Basically, it creates a VBS file that will be executed to install the malware on the user machine. Once exploited, the help center process is killed using the “taskkill” command line utility (command line process killer).

Java Parse Midi vulnerability : CVE-2010-0842 – April 2010

A quick look into “pap.class” reveals the exploit used:

If we have a look at the payload of this exploit in a hex editor, it confirms the vulnerability used, as can be seen in the highlighted code:

Navigation Method Cross-Domain Vulnerability – CAN-2004-0549 (ms04-25)

This one is the oldest vulnerability used by the Incognito Exploit Kit. This vulnerability is from 2004. The targeted software is Internet Explorer and allows remote code execution:

Malicious PDF

Exploit kits often come with a malicious PDF, and Incognito does as well.

An iframe to a malicious PDF file is also created by the main exploit kit page. The PDF uses four vulnerabilities. The obfuscated PDF uses JavaScript to exploit the vulnerabilities. Depending of the version of Adobe Reader, the following exploits are triggered:

Adobe Reader Collab GetIcon CVE-2009-0927

Adobe Reader util.printf CVE-2008-2992

Adobe Reader newPlayer CVE-2009-4324

Adobe Reader CollectEmailInfo CVE-2007-5659

What lessons can be learned from this Japan spam campaign? A lot of people still don’t update their computers, especially the 3rd party applications. The most recent vulnerability exploited in the kit is from June 2010, and the oldest is from 2004.

I will reiterate my recommendations from my previous blogs to emphasize them:

Past experience tells us that cybercriminals are always trying to make profit out of natural disasters or big news in general. If you want to get the latest news on such events, we strongly recommend that you browse legitimate news sites and never follow links received by email, or on social networks.

It’s also very important to keep your system up to date, be it the operating system or third party applications such as Java, PDF readers, Browsers etc.

And finally, keep your security solutions up to date.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/japan-quake-spam-leads-to-malware-part-3/29771/