ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Military Hardware and Men

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2012-0158
Remote Code Execution in Microsoft MSCOMCTL.OCX (Windows Common Controls)

CVE-2012-0158 is a remote code execution flaw in Microsoft's MSCOMCTL.OCX, the Windows Common Controls ActiveX component, where improper handling of crafted input allows memory corruption and code execution. It is typically triggered when an application that uses the control (most commonly Microsoft Office) processes specially crafted content, such as a malicious document or file, meaning a victim usually has to open attacker-supplied content. Successful exploitation lets an attacker run arbitrary code and take complete control of the affected system with the privileges of the current user. Any Windows system carrying a vulnerable copy of MSCOMCTL.OCX — including systems where the control was redistributed by legacy applications — is affected, which makes the potential population very large. Exploitation is confirmed and ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and EPSS assigns it the maximum reported probability of exploitation within 30 days.

Do: Apply the Microsoft security update for MSCOMCTL.OCX (per vendor instructions, per CISA's required action) on all systems, prioritizing endpoints and servers that open Office documents. Because exploitation commonly arrives via malicious documents, treat unsolicited Office/RTF attachments with suspicion and verify that applications that redistribute MSCOMCTL.OCX have installed a patched copy. Scan the estate for the presence and version of MSCOMCTL.OCX, especially on legacy Windows/Office installations that may be missed by routine patching.

100% KEV ransomware
  • Microsoft MSCOMCTL.OCX
masshundreds of millions of Windows systems potentially affected
Full article565 words · extracted from securelist.com · click to collapse

Over the last few months we have seen a series of very similar targeted attacks being blocked in our Linux Mail Security Product. In each case the documents used were RTF and the exploit was CVE-2012-0158 (MSCOMCTL.OCX RCE Vulnerability).

The attacks seem to be from the same group and most appear to be sent from Australia or Republic of Korea. The sender IP addresses vary but many are sent via mail.mailftast.com. This domain is registered in China:

1

2

3

4

5

6

7

8

9

REGISTRANT CONTACT INFO

liu runxin

No.1,Nanjing Road

Shanghai

Shanghai

200001

CN

Phone:+86.2164415698

Email Address:<span class="mail">lishd2011@163.com</span>

The documents are in three categories:

  1. The first group of documents are related to articles on the Men-s Health website. These are some example filenames:

    1

    2

    3

    4

    5

    EAT FORBETTER SEX.doc

    How tolast longer inbed.doc

    6Awkward Sex Moments,Defused.doc

    9ways tohave better,hotter,andmore memorable sex.doc

    10Ways toGet More Sex.doc

  2. The second group are military related:

    1

    2

    3

    Stealth Frigate.doc

    The BrahMos Missile.doc

    How DRDO failed India'smilitary.doc

  3. The third set have Cyrillic filenames:

    1

    2

    3

    4

    приоритетысотрудничества.doc

    Списокучастниковрабочейгруппы(0603-2013).doc

    Списоккадров.doc

    ПриглашениеМИОМТЕЙКОВО2013.doc

Most weeks we will see one topic from categories 1 and 2 and several using Cyrillic filenames. The exploit, shellcode and malware used tend to be the same. The only real different is the decoy documents displayed when the exploit runs.

Here are two examples from last week:

Stealth Frigate.doc

EAT FOR BETTER SEX.doc

The metadata for the decoy documents is the same and it looks like it hasn-t be updated for a while.

The title translates as ?The financial result for the first 9 months of 2012¦ and the company name relates to a Russian submarine manufacturer.

When the exploit runs it creates and executes a file called wordupgrade.exe. This executable drops a DLL called usrsvpla.dll into the system32 directory and modifies the WmdmPmSN (Portable Media Serial Number Service) registry key to load the DLL into svchost.exe.

Both wordupgrade.exe and usrsvpla.dll contain the PDB path:

The malware installed by these documents is a variant of Enfal/Lurid. We are detecting wordupgrade.exe as Trojan-Dropper.Win32.Datcaen.d and usrsvpla.dll as Trojan.Win32.Zapchast.affv. Our colleagues from Trend have previously described this malware in their papers.

https://blog.trendmicro.com/trendlabs-security-intelligence/modified-enfal-variants-compromised-874-systems/

http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_dissecting-lurid-apt.pdf

The samples seen last week contact a C&C server at yui.bcguard.com. This domain has the same registration details a mailftast.com above.

Below are the IP addresses of these domains:

1

2

yui.bcguard.com-208.115.124.90(China)

mail.mailftast.com-142.234.156.3(US)

There are several other domains registered to ?liu runxin¦:

1

2

3

4

5

6

timmf.com

bcbtheory.com

bellbuttons.com

atmdzxgs.com

coffeeibus.com

cymdbd.com

Conclusion

The malware used in these attacks is not very advanced or new (Enfal variants have been seen as far back as 2006). However, the attacks are very regular, so it is probably safest not to open attachments related to these topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/military-hardware-and-men-s-health/67055/