First Glimpse into MS08-067 Exploits In The Wild
Friday October 24, 2008 at 5:53 am CST
Posted by Geok Meng Ong
It has been over 2 years since I last wrote about malware exploitation of a major vulnerability in the Windows Server Service (MS06-040) by malware.
In 2006, worm authors were quick to adopt the remotely executed exploit in just 4 day following a security update released as part of the regular Patch Tuesdays - IRC-Mocbot, W32/Sdbot, W32/Spybot, W32/Opanki, et ceteras.
Now in 2008, we are faced with malware authors, motivated by profits, more organized, and are more likely to target zero-day vulnerabilities, as we have reported on several critical incidents we have discovered since 2006. Like déjà vu, Microsoft released an out-of-cycle security update today to address in-the-wild attacks against a new MS08-067 vulnerability targeting the same Windows Server Service.
Attacks seen in the wild so far seem to have come from variants of the Spy-Agent.da trojan. When run, it may not be immediately apparent to the victim that it was using any exploits. Taking a quick glimpse into the binary code of basesvc.dll (Spy-Agent.da.dll), one of the DLL components installed by Spy-Agent.da, one can see strings that would look very familiar to those familiar with MS06-040.

On closer analysis, Spy-Agent.da.dll seeks out potentially vulnerable Windows machines in the local network, and sends maliciously crafted DCERPC requests to exploit the Server Service (SvrSvc).

When successful, hardcoded shellcode embedded within the malware, is executed on the targeted machines to download Spy-Agent.da (or possibly other variants or files) from a web server hosted in Japan.

(shellcode after decoding)
Just hours following the patch release, public source code has already been seen distributing on the Internet. What more can I say ? Patch your systems ! Yes, NOW !
Spy-Agent.da and Spy-Agent.da.dll are now detected using the current 5414 DATs. See Dave’s blog for McAfee’s coverage.
(thanks to Joey Koo and Xiaobo Chen for providing analysis data and packet dumps used in this blog)

October 24th, 2008 at 10:18
[...] First Glimpse into MS08-067 Exploits In The Wild [...]
October 24th, 2008 at 12:35
[...] McAfee has a nice description of the exploit code as well. [...]
October 24th, 2008 at 14:17
Critical MS Vulnerability…
Microsoft released a critical “out band” patch this afternoon regarding a critical vulnerability with RPC/DCOM service.The vulnerability has been exploited in limited circumstances in the wild. SANS has been tracking the info and is good place for to…
October 24th, 2008 at 20:25
The data execution prevention feature is not normally used, as there is too much legitimate self-modifying code. Patch.
-Tom
October 25th, 2008 at 02:02
How viable is this worm and successful is it at spreading on its own?
October 25th, 2008 at 21:18
Hi,
I have been already gotten those samples.
And they can be detected in the 5414 DAT.
Thanks for your help.
October 30th, 2008 at 07:19
[...] worm to attack other hosts in the networkFirst Glimpse into MS08-067 Exploits In The Wildhttp://www.avertlabs.com/research/blog/index.php/2008/10/24/first-glimpse-into-ms08-067-exploits-in-…Gimmiv - Additional Information [...]
October 30th, 2008 at 07:20
[...] worm to attack other hosts in the networkFirst Glimpse into MS08-067 Exploits In The Wildhttp://www.avertlabs.com/research/blog/index.php/2008/10/24/first-glimpse-into-ms08-067-exploits-in-…Gimmiv - Additional Information [...]
November 5th, 2008 at 07:01
[...] As most of you now know, on 10/23, Microsoft announced a critical out-of-cycle patch (MS08-067) to fix a flaw being exploited by cybercrooks. [...]
November 19th, 2008 at 09:43
[...] マイクロソフトは今回新たに判明した,全く同じServerサービスに関係するセキュリティ・ホール「MS08-067」への措置として,緊急のセキュリティ更新プログラムをリリースした [...]
December 9th, 2008 at 07:48
[...] I have lost count of how many blogs I have written this year that has anything to do with 0-day or unpatched [...]