New Uyghur and Tibetan Themed Attacks Using PDF Exploits
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2009-0563 | Buffer Overflow RCE in Microsoft Office via Crafted Word Document CVE-2009-0563 is a buffer overflow (CWE-119) in Microsoft Office in which a Word document containing a crafted tag with an invalid length field overflows a buffer when the document is parsed. An attacker triggers the flaw by persuading a user to open a maliciously crafted Word file, typically delivered via email or a download. Successful exploitation yields remote code execution running in the context of the user who opened the document, allowing the attacker to install or run software, or view and change data. Any user of an affected Microsoft Office release is exposed; the CISA catalog lists the affected product simply as Microsoft Office. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2022-06-08, EPSS assigns a 63.1% probability of exploitation within 30 days, and the related headlines describe APT backdoor campaigns against Mac users consistent with targeted use of this flaw. Do: Apply Microsoft security updates per vendor instructions, and upgrade or fully patch legacy Office installations that no longer receive updates, verifying that no endpoints (including Mac systems, given reported APT activity) remain on unpatched versions. Treat unsolicited Word documents as untrusted and monitor for suspicious processes spawned by Office when documents are opened. Because this flaw is KEV-listed with known in-the-wild exploitation, prioritize patching and hunt for document-opening activity consistent with targeted attacks. | — | 63% | KEV |
| mass≈100M+ users (Office's global install base; remaining unpatched legacy installs plausibly in the millions) | |
| CVE-2010-3333 | Stack Buffer Overflow in Microsoft Office RTF Parsing Allows Remote Code Execution CVE-2010-3333 is a stack-based buffer overflow in the way Microsoft Office parses RTF (Rich Text Format) data. An attacker triggers it by convincing a user to open a specially crafted RTF file, including an RTF email that is handed to Office for rendering, with no authentication required beyond the user's action. Successful exploitation allows remote code execution in the context of the logged-on user, giving the attacker a foothold on the workstation. Any Microsoft Office installation within the affected range identified in the December 2012 Microsoft security bulletin is exposed; the source data does not enumerate specific version numbers. The flaw is actively exploited: it is on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03, ransomware association unknown) and was used in targeted espionage, notably Kaspersky's 'Red October' campaign, with EPSS estimating an 89.5% probability of exploitation within 30 days (100th percentile). Do: Apply the Microsoft updates from the December 2012 security bulletin that fixes this RTF parsing flaw across all Office/Word installations, prioritized given the ~90% EPSS score and CISA KEV listing. As interim mitigation, block or inspect inbound RTF attachments at email gateways and configure Outlook to read email in plain text so RTF content does not open automatically in Office. Inventory legacy or unpatched Office installations that may have missed the 2012 update, since these remain the likely current exposure. | — | 89% | KEV |
| masshundreds of millions of Office users/installations at time of disclosure (current unpatched legacy installs unknown) | |
| CVE-2013-0640 | Memory Corruption RCE in Adobe Reader and Acrobat (acroform.dll) CVE-2013-0640 is a memory corruption flaw (out-of-bounds write, CWE-787) in acroform.dll, the AcroForm PDF-forms component of Adobe Reader and Acrobat, which can be triggered by opening a specially crafted PDF. An attacker who tricks a user into opening a malicious PDF gains remote code execution with the privileges of the logged-on user; this was the vector used by the MiniDuke espionage campaign of February 2013, which delivered a small government-grade backdoor assembler backdoor via PDF 0-day exploits. Anyone running unpatched Adobe Reader or Acrobat is affected, and F-Secure's discovery of in-the-wild MiniDuke samples plus Uyghur- and Tibetan-themed PDF attacks confirm active targeted exploitation. The bug carries a very high likelihood of exploitation (EPSS 87%, 100th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03 with required action to apply vendor updates; no public PoC is catalogued, but in-the-wild exploitation is confirmed. Do: Apply updates per vendor instructions (the CISA KEV required action): bring all Adobe Reader and Acrobat installations to the latest patched release issued by Adobe in February 2013 or later. Inventory endpoints for outdated PDF readers, block or inspect PDFs from untrusted sources as an interim mitigation, and check government/NGO-type targeted machines for MiniDuke-style PDF-borne backdoor indicators. | — | 87% | KEV |
| masshundreds of millions of users (Adobe Reader/Acrobat is near-universal on desktops) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 7005e9ee9f673edad5130b3341bf5e5f | (ItaDuke) exploits. Some of the MD5s and filenames include: 7005e9ee9f673edad5130b3341bf5e5f 2013-Yilliq Noruz Bayram Merik isige Teklip.pdf d00e4ac94f1 |
| md5 | 92f15c2b82e81e8ae47e361b3ecb5add | 204,932 bytes (MD5 varies) MSTD32.DLL – 31,880 bytes (MD5: 92f15c2b82e81e8ae47e361b3ecb5add) MSTD32.DLL is signed by “YNK JAPAN Inc”, with a certificat |
| md5 | ad668992e15806812dd9a1514cfc065b | df d00e4ac94f1e4ff67e0e0dfcf900c1a8 .pdf (joint_letter.pdf) ad668992e15806812dd9a1514cfc065b arp.pdf The Kaspersky detection name for these exploits is |
| md5 | d00e4ac94f1e4ff67e0e0dfcf900c1a8 | b3341bf5e5f 2013-Yilliq Noruz Bayram Merik isige Teklip.pdf d00e4ac94f1e4ff67e0e0dfcf900c1a8 .pdf (joint_letter.pdf) ad668992e15806812dd9a1514cfc065b ar |
Full article919 words · extracted from securelist.com · click to collapse
On Feb 12th 2013, FireEye announced the discovery of an Adobe Reader 0-day exploit which is used to drop a previously unknown, advanced piece of malware. We called this new malware “ItaDuke” because it reminded us of Duqu and because of the ancient Italian comments in the shellcode copied from Dante Alighieri’s “Divine Comedy”.
Previously, we posted about another campaign hitting Governments and other institutions, named Miniduke, which was also using the same “Divine Comedy” PDF exploits.
In the meantime, we’ve come by other attacks which piggyback on the same high level exploit code, only this time the targets are different: Uyghur activists.
Together with our partner at AlienVault Labs, we analyzed these new exploits. For their blog, which includes Yara rules and industry standard IOC’s, please read [here]. For our analysis, please read below.
The new attacks
A few days ago, we observed several PDF files which carry the CVE-2013-0640/641 (ItaDuke) exploits. Some of the MD5s and filenames include:
7005e9ee9f673edad5130b3341bf5e5f 2013-Yilliq Noruz Bayram Merik isige Teklip.pdf
d00e4ac94f1e4ff67e0e0dfcf900c1a8 .pdf (joint_letter.pdf)
ad668992e15806812dd9a1514cfc065b arp.pdf
The Kaspersky detection name for these exploits is Exploit.JS.Pdfka.gjc.
If the exploit is successful, the PDFs show a clean, “lure” document to the user:


The first document (2013-Yilliq Noruz Bayram Merik isige Teklip.pdf) refers to a New Years party invitation. The second one, “arp.pdf”, is an authorization to request a reimbursement, for a Tibetan activist group.
The Javascript exploit code has a large comment block prepended, which was probably included to avoid detection by certain anti-malware programs.

The comment block and the exploit is exactly the same among all analyzed PDF files. Interestingly, the “sHOGG” string obfuscation function from Itaduke has been removed. In addition, some of the obfuscation for variable initialization has been removed as well:

All documents drop the same malware, detected by Kaspersky as Trojan.Win32.Agent.hwoo and Trojan.Win32.Agent.hwop, which is interesting: this is one of the rare cases when the same threat actor hits both Tibet and Uyghur activists at exactly the same time. It is possible this was done in regards to a human rights conference which is taking place in Geneva between 11-13 March, 2013.
The backdoor
The PDF malware dropper creates a file named “C:Documents and SettingsAdministratorLocal SettingsTempAcroRd32.exe” and runs it. AcroRd32.exe has a PE compilation timestamp of “Wed Jul 11 05:39:45 2012”.
“AcroRd32.exe” contains an encrypted block with the final payload, an 8KB backdoor, which is dropped as “clbcatq.dll” and run via Windows Update. The block can be easily noticed inside the backdoor by a trained eye:

The block is encrypted with a simple xor + add algorithm. Here’s the decryption algorithm for the final payload:
char key[]=”0l23kj@nboxu”;
a=key[i&7] + 6;
buf[i]=(buf[i]^a) + a;
The final backdoor (clbcatq.dll) is 9728 bytes in size. It was compiled on “Wed Jul 11 05:39:39 2012”. The backdoor connects to its C&C server and requests further data using HTTP GET requests. The response from the server is expected to be a slightly encrypted DLL, which is then loaded and called by exports “InfectFile” and “GetWorkType”.

For all the servers, the malware makes a request to “/news/show.asp”, using a custom agent string of “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)”.
At the moment, all the domains point to the same IP address: 60.211.253.28. The server is located in China, in Shandong province:

The domains “micrsofts.com” and “hotmal1.com” appear to have been registered by the same person, although with very small differences in the registration data:
Registrant Contact:
GW SY
li wen li wen ([email protected])
zq dj
jiningshi, shandongsheng, cn 272000
P: +86.05372178000 F: +86.05372178000
Registrant Contact:
GW SY
li wen li wen ([email protected])
zq dj
shixiaqu, beijingshi, cn 272000
P: +86.02227238836601 F: +86.02227238836601
Stage 2
The command and control server will reply with a 300K backdoor, which is sent in encrypted form. Here’s how it looks as sent by server:

The encryption is a sub 0x11 followed by a xor 0x11. Once decrypted, we get the malware dropper, which was compiled on “Wed Jul 11 06:52:48 2012”. This “stage 2” malware dropper is heuristically detected by Kaspersky products as HEUR:Trojan.Win32.Generic.
The stage 2 dropper will install two files in system32wbem:
4BA5E980.PBK – 204,932 bytes (MD5 varies)
MSTD32.DLL – 31,880 bytes (MD5: 92f15c2b82e81e8ae47e361b3ecb5add)
MSTD32.DLL is signed by “YNK JAPAN Inc”, with a certificate that was revoked by the issuer:

This technique reminds us of the method used by the malware from the Tilded platform (Duqu, Stuxnet) for starting up (small signed loader which reads and executes main body kept in encrypted form).
Our colleagues from Norman have previously written (http://blogs.norman.com/2011/security-research/invisible-ynk-a-code-signing-conundrum) about this compromised certificate in relation to Hupigon and other malware.
The final stage malware is known by our products as Trojan.Win32.Swisyn and has pretty extensive functionality for data stealing.
Conclusions
We have previously published blogs about targeted attacks against Tibetan and Uyghur activists.
The threat actors behind these attacks are very active and continuously use new methods and new exploits to attack their victims. We have previously seen the use of CVE-2013-0158 or CVE-2010-3333, in addition to exploits for Mac OS X, taking advantage of CVE-2009-0563.
The PDF exploit originally discovered by FireEye is the first known exploit capable of bypassing the Adobe Reader X sandbox. Due to this advanced capability, it is extremely valuable to any attacker. Although it was probably developed for (or by) use of a nation state originally, we now see it being copied and reused by other threat actors. This is becoming a common procedure nowadays and we can expect more such piggybacking or exploit stealing in the future.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/new-uyghur-and-tibetan-themed-attacks-using-pdf-exploits/35465/