Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Another Exploit Targets IE7 Bug

    Cybercriminals are actively exploiting a critical vulnerability in Internet Explorer 7, which arises from the browser’s improper handling of errors when attempting to access deleted objects. This vulnerability allows remote attackers to execute arbitrary codes on a vulnerable machine.

    The threat starts with a spammed malicious .DOC file detected as XML_DLOADR.A. This file has a very limited distribution script, suggesting it may be a targeted attack. It contains an ActiveX object that automatically accesses a site rigged with a malicious HTML detected by the Trend Micro Smart Protection Network as HTML_DLOADER.AS.

    HTML_DLOADER.AS exploits the CVE-2009-0075 vulnerability, which is already addressed by the MS09-002 security patch released last week. On an unpatched system though, successful exploitation by HTML_DLOADER.AS downloads a backdoor detected as BKDR_AGENT.XZMS.

    This backdoor further installs a .DLL file that has information stealing capabilities. It sends its stolen information to another URL via port 443.

    This is how the threat works.
    Figure 1. Threat Infection Chain.

    Although the install base of the IE family is slowly eaten up by stiff competition such as Firefox and Chrome, IE7 is used by about one in every four Web users, a much larger share than previous versions of IE. This could explain why cybercriminals seem to be eagerly searching for more bugs. Zero-day exploits, also in IE7, were big news last December:

    Our engineers are still working on the details of this threat. We will post updates as soon as more information becomes available. The Smart Protection Network already prevents HTML_DLOADER.AS, XML_DLOADR.A, and BKDR_AGENT.XZMS from running in systems. It also blocks malicious URLs. Users meanwhile are advised to PATCH NOW!

    Update as of 17 February 2009, 6PM PST

    Analysis by Trend Micro researchers reveal that BKDR_AGENT.XZMS takes screenshots of the infected system and sends these screenshots to a remote malicious location. It also creates a hidden Internet Explorer window which connects to a website to listen for commands.

    Update as of 1 March 2009, 7PM PST

    Advanced Threats Researcher Jamz Yaneza points at some details that may link this attack to the wave of exploits related to the Beijing Olympics frenzy last year, as well as the related problem regarding Tibet. The previous exploits also used specially crafted MS documents. BKDR_AGENT.XZMS meanwhile contains a string related to the 50th anniversary of the Tibetan uprising. The backdoor also waits for commands from a website in China, which interestingly is linked to port-scanning and SQL attacks before.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    26 Responses to “Another Exploit Targets IE7 Bug”

    Trackbacks

    1. Targeted malware attacks exploiting IE7 flaw detected | Zero Day | ZDNet.com
    2. Technology News » New exploit targets IE 7 hole patched last week
    3. Internet Explorer Exploit für kürzlich geschlossene Lücke | seibotec
    4. Internet Explorer » Blog Archive » Another Exploit Targets IE7 Bug | Malware Blog | Trend Micro …
    5. Internet-Explorer-Backdoor macht Screenshots - Security | News | ZDNet.de
    6. Internet Explorer » Blog Archive » Another Exploit Targets IE7 Bug | Malware Blog | Trend Micro
    7. Linkpost | 2.18.2009 | 226bw Tech News Blog
    8. alexbobica (alexbobica)
    9. Mac.Intosh » Wednesday, February 18, 2009
    10. Another Exploit Targets IE7 Bug - Computer Forums
    11. Crow74 (Theo)
    12. Aprovechan vulnerabilidad en Internet Explorer 7 a través de documentos Word « arrayexception.com - Tecnologia y Desarrollo
    13. Trend Micro: attenti al trojan cinese - The Inquirer IT
    14. Malware targets Internet Explorer 7 Bug | The Fiery Source
    15. Windows e vulnerabilità: IE7 ancora sotto attacco | Yourpage live news aggregator
    16. Open Systems Journal » Blog Archive » Internet Explorer Vulnerability Attack Vectors
    17. New exploit targets IE 7 hole patched last week - The Web World
    18. Aprovechan vulnerabilidad en Internet Explorer 7 a través de documentos Word
    19. Infectado a través de Explorer… ¡aunque no lo uses! : Un lugar en el mundo…
    20. חור חדש ... זהירות לא להפגע - TheMarker Cafe
    21. Softwares and Wallpaper For Educational Needs » Blog Archive » New exploit targets IE 7 hole patched last week
    22. [Information Week] Hackers use ie7 exploit - Overclock.net - Overclocking.net
    23. MS-DEFCON 2: Problems with the patches - and an exploit @ AskWoody.com
    24. Aprovechan vulnerabilidad en Internet Explorer 7 a través de documentos Word | FusionGT V 2.0
    25. Patched IE7 Flaw Attacked | TechIndia
    26. SalDee.com » Malware Finds Point of Entry in Internet Explorer 7 Bug


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice