New Wave Of Web Attacks Exploits Office
Monday July 13, 2009 at 10:41 pm CST
Posted by Haowei Ren
Today, Microsoft released a security advisory on active attacks in the wild using a vulnerability in Microsoft Office Web Components. Computers installed with Microsoft Office features that uses vulnerable versions of the Microsoft Office Web Components could be infected with malware when browsing upon malicious websites in Internet Explorer.
From our investigation, Exploit-CVE2009-1136, a new 0-day exploit was added into web exploit toolkits that widely released Exploit-MSDirectShow.b on hijacked websites in China just the previous week. Since the start of this new wave of attacks, new trojans installed by Exploit-CVE2009-1136 has been detected by Artemis technology which also allow us to get a global view of the spread of this new threat.
In one of the new trojan samples used by Exploit-CVE2009-1136, we first saw Artemis queries coming from China at 11:53 GMT on July 13th, 2009. We didn’t have automatic protection for this at this point, but various systems analyzing the threat details soon mark this as malicious.
By now, this sample has spread to many other Internet users in China, and is now queried and blocked by Artemis more than 328 times at more than 145 unique IP addresses (ISP , not end point).
Besides China, we only saw Artemis queries coming from Virus Total (Spain) and fellow malware researchers in the UK and Germany in small numbers.
We will post more information as we receive it.

February 10th, 2009 at 11:21
[...] David Scharoun, ricercatore dei McAfee Avert Labs, ha inserito all’interno del blog il suo commento relativo a quest’ultima ondata di spam di San Valentino al seguente indirizzo: http://www.avertlabs.com/research/blog/index.php/2009/02/. [...]
July 15th, 2009 at 05:59
[...] da parte di pirati informatici sopratutto provenienti dal’EST Asiatico, come avvertono i McAfee Labs. McAfee Threat [...]
July 20th, 2009 at 09:42
[...] Para saber mais: McAfee Labs [...]
October 11th, 2009 at 00:48
[...] [...]
November 10th, 2009 at 07:51
[...] No Comments Trackback Warning to all Pacquaio and Cotto fans. Bad guys are taking advantage of their upcoming fight. Searching for “Pacquiao VS Cotto” could lead to Fake AntiVirus programs. [...]