Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > Zero-Day IE Flaw Being Actively Exploited

    Microsoft’s recent security updates fail to provide protection against a recently discovered zero-day vulnerability, which could provide opportunities for cyber criminals to compromise PCs.

    Several websites were found rigged with a malicious JavaScript detected by Trend Micro as JS_DLOAD.MD. This script exploits this zero-day vulnerability in Internet Explorer, through a Heap Spray on SDHTML. It also checks for the IE version installed on the affected system, since this exploit targets IE7.

    After a successful exploit, it triggers a series of redirections to multiple URLs, then finally connects to one of several different domains — a full list of malicious domains can be found over at ShadowServer, as they have been verifying the domains collected by them and from other security researchers across the industry.

    We detect the downloaded files as the following:

    • TSPY_ONLINEG.EJH
    • TSPY_ONLINEG.EJG
    • TSPY_ONLINEG.HAV
    • TSPY_ONLINEG.ADR

    The toolkit related to this exploit is reportedly being sold in the China underground community. This is quite logical, since TSPY_ONLINEG variants are notorious info-stealers — particularly stealing credentials related to online games, which in turn are very popular in China.

    The Trend Micro Smart Protection Network provides protection to users at a desktop level, with all related malicious domains blocked, and files detected. However, this recently discovered flaw remains unpatched by Microsoft.

    The SANS Internet Storm Center (ISC) also has additional information posted on this issue in their Daily Incident Handler’s blog.

    This threat bears strong resemblance to a couple of attacks we’ve seen this year, which were primarily targeting Chinese gamers:

    Update as of 11 December 2008, 12:00 AM PST:

    Trend Micro Researchers have found another sample of the said malware that downloads the file explorer.exe, which is now detected as RTKT_BUREY.C.

    Update as of 12 December 2008, 4:00 AM PST:

    Microsoft updated their Security Advisory initially published December 10. The update confirms that this zero-day vulnerability not only affects Internet Explorer 7 (IE7), but also all version of Internet Explorer.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    18 Responses to “Zero-Day IE Flaw Being Actively Exploited”

    Trackbacks

    1. Zero Day mobile edition
    2. Rich_at_Dell (Richard Bernier)
    3. Jean Ghalo — Where It All Begins :: Microsoft IE Big Security Hole
    4. Security Alert Issued for Internet Explorer Zero-Day Flaw | Community Site News
    5. Serious security flaw found in IE 7 use alternative - Life Burner
    6. Si usas Internet Explorer, abandónalo - al menos una temporada » El Blog de Enrique Dans
    7. Grave vulnerabilidad en algunas versiones de Microsoft Explorer « Que no! Que no me da la gana de tener un blog
    8. Twitter_Tips (Tips, Tools, Status)
    9. CreativeWisdom (Leah Dossey)
    10. techstud (Jason C. )
    11. paulawhite (Paula White )
    12. MassRon (MassRon)
    13. Divapalooza (Angela Stevens)
    14. DaveSinkula (DaveSinkula)
    15. IE7 Users Cautioned! | Pinoy Gaming Network: Game Reviews and Technology News for Filipino Gamers and Enthusiasts
    16. Microsoft: Big Security Hole in All IE Versions | MCI Cabinetry and Furniture Inc.
    17. No utilizar Internet Explorer durante un tiempo. « - SyLmaX -
    18. ABANDONA INTERNET EXPLORER | tonorama


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice