Microsoft warned about malicious spam campaigns using vulnerabilities in Office and Wordpad
Microsoft recently issued an emergency warning about an online spam campaign targeting European countries, currently using an exploit can easily infect users by simply opening an attachment. .
In a series of tweets posted from Microsoft Security Intelligence accounts on Twitter, Microsoft has repeatedly issued warnings that it has discovered a malicious campaign containing RTF attachments that abuse the CVE-2017 vulnerability. -11882 in Microsoft Office and Wordpad.
Example attached to the CVE-2017-11882 exploit
- Hacker revealed the second Zero-Day, broke Windows' EoP vulnerability patch
When successfully exploited, this vulnerability can automatically infect users by simply opening a malicious attachment.
Microsoft Security Intelligence Alerts on Twitter
- GoldBrute botnet campaign is trying to hack 1.5 million RDP servers worldwide
The CVE-2017-11882 vulnerability allows RTF and Word documents to be created to automatically execute certain commands after opening. This vulnerability has been successfully patched in 2017, but in fact, Microsoft continues to record small exploits used in attacks, especially showing signs of increasing. both in quantity and scope of impact in the past few weeks. Originally written by Microsoft as follows:
"Notably, Microsoft's security team has recorded a rapid increase in the number of malicious activities related to the CVE-2017-11882 vulnerability in the past few weeks. We really recommend you. Should apply the latest security updates to ensure the safety of your system ".
According to Microsoft experts, when the attachment is opened, it will "execute a large number of scripts of different types (VBScript, PowerShell, PHP, and others) to download the payload to the system. victim '.
Researchers conducted one of the sample documents, when opening the document, it immediately began executing a script downloaded from Pastebin, executing the PowerShell command. This PowerShell command will then download an encrypted file named base64 and save the file to % temp% bakdraw.exe.
Script and malware are being downloaded
- Microsoft Azure is being used to host malware and C2 servers
Next, a copy of bakdraw.exe will be copied to the % UserProfile% AppDataRoamingSystemIDE address , and at the same time a scheduled task (Scheduled Task) named SystemIDE will be configured to start executing as well as modifying add sustainability.
Scheduled Task
- Discovery of Trojan scattering steals virtual money through YouTube
The Microsoft side claims that this executable file is a backdoor currently configured to connect to a malicious domain that is no longer accessible. This means that although the computer will be infected, the backdoor will still not be able to communicate with its own command and control server (C2 server) to receive the command.
However, this payload can still easily be used for other forms of attack, so Microsoft recommends that all Windows users install the latest security update for this vulnerability as soon as possible.
The recent CVE-2017-11882 vulnerability has also been discovered by the FireEye team, and is currently being used in a campaign targeting several Central Asian regions, and establishing a new backdoor called HawkBall. . It is still unclear whether these campaigns are linked.
You should read it
- Office security with Microsoft Office (Part I)
- Summary of popular network attacks today
- Microsoft is testing ads in WordPad on Windows 10
- Microsoft's Windows and Office stick with serious flaws
- Trojans appear to attack Microsoft Office
- Viewing GIFs can also be hacked for Microsoft Teams account
- Microsoft patched a critical vulnerability in Windows
- Hacker exploited three vulnerabilities in Microsoft Office to spread Zyklon malware
May be interested
- Hackers break into chats on Microsoft Teams to spread malwareinternational security researchers have just warned about a relatively new form of attack related to the traditional enterprise application platform microsoft teams.
- How to Open WordPad in Windows 10wordpad is a free and simple word processing application that was introduced in windows 95 and is still around in windows 10. it is not as simple as notepad nor advanced as microsoft word, and it is somewhat limited.https://en.wikipedia....
- Hackers are using new Microsoft Office vulnerabilities to distribute malwarehackers are exploiting vulnerabilities in microsoft office software to spread a kind of sophisticated malware capable of stealing certificates, exploiting cryptocurrency and conducting denial of service (ddos) attacks.
- Warning: Microsoft and Google Clouds are being abused to launch large-scale phishing campaignsstatistical results show that in the first quarter of 2021 alone, global criminals sent 52 million malicious messages by abusing well-known storage services such as office 365, azure, onedrive, sharepoint. , g suite and firebase.
- Microsoft Office 365 version is supported against blackmailmicrosoft will add some new features including personal and home, in office 365 versions to consumers.
- Spam strongly attacks social networksaccording to symantec depository service (symantec hosted services), spam distribution containing shortened url has peaked 23.4 billion spam in one day
- 8 useful applications to replace Microsoft OneNotemicrosoft onenote is a microsoft application, it is different from other applications like notepad or wordpad, can collect all kinds of digital information including text, images, videos, web clips ...
- What is spam? How is it understood in Zalo, LoL, Facebook ...what is the meaning of spam? in this article, network administrator will invite you to follow along to find out the answers.
- Link Download Microsoft Office 2019microsoft office is a family of software and client & server services developed by microsoft. originally the term for office suites - microsoft's bundled productivity suite. the first version of microsoft office contained microsoft word, microsoft excel and microsoft powerpoint.
- Microsoft warns of phishing campaigns targeting Outlook Web App and Office 365 usersmicrosoft security experts issue an important warning about an ongoing large-scale phishing, targeting outlook web app (owa) services and office 365.