Archive for September 19th, 2006


Sep19
by Jhoevine Capicio (Advanced Threats Researcher)

Sunbelt has just discovered a new IE zero day being used in the wild. The zero day exploit makes use of a vulnerability in the Vector Markup Language (VML) inside Internet Explorer to overflow a buffer and inject a shellcode.


I will update this as research on the said subject is still on going.


Update (Jovs, Tue, 19 Sep 2006 10:37:07 PM)


For those who don’t know, the vulnerable dll exploited by this zero day is VGX.DLL which is used by Internet Explorer for processing Virtual Markup Language.


Sunbelt has proposed turning off Javascripting to mitigate the exploit. Or you can just use an alternative browser like Firefox.


Microsoft has already been informed about the vulnerability, so far there isn’t a patch available yet, but give them time, it is a zero day after all.


This blog will be updated for the malware name given to the exploit code.



Update (Chachi, Wed, 20 Sep 2006 03:08:05 AM)


The exploit code will now be detected as EXPL_EXECOD.A and the executable files will be detected as TROJ_AGENT.FAC, TROJ_DELF.DBC, TROJ_DLOADER.EES.


These are now detected using Control Pattern 3.764.02


If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!

 
Posted in Uncategorized |

Sep19
by Roberto Tayag (Threats Analyst)

As of this writing we have already received a total of 1,335 Samples in a couple of hours. Trend Micro has already detected this threat as TROJ_CLAGGE.B using OPR 3.759.00.


The malware comes as an attachment to emails with the filename Rechnung.zip or Rakningen.zip(7,028 Bytes). Please be wary of emails you receive with those attachments, do not atempt to open them. If you want more information on what the malware is capable of check our Virus encyclopedia here.


We are still looking into the details of this spammed malware, as of now please be very careful of attachments with the aforementioned filenames in your inbox.

 
Posted in Uncategorized |


© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice