Jump to content

Unpatched Microsoft Word DDE Exploit Being Used In Widespread Malware Attacks


hacker7

Recommended Posts

 
 
 
 
 
 
 
 
 
 
 
 
 
 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


 


 
 


 


 

 

 

 


 

ٍSource

Link to comment
Share on other sites


  • Replies 12
  • Views 1.3k
  • Created
  • Last Reply

M$ office  not only causes a lot  of problems  with malware on Windows it's the #1 cause of malware on MAC OS  too.  I don't use M$ office at home  but some others on my network do is this not already been mitigated by Anti-malware?  :s

 

DEE Exploit via filehost  .exe  type spoted in the wild on Filefactroy

https://virustotal.com/en/file/316f0552684bd09310fc8a004991c9b7ac200fb2a9a0d34e59b8bbd30b6dc8ea/analysis/

Word DEE Exploit

https://www.virustotal.com/en/file/1a1294fce91af3f7e7691f8307d07aebd4636402e4e6a244faac5ac9b36f8428/analysis/

Yes it has to answer my own question . :dance2:

Link to comment
Share on other sites


9 hours ago, steven36 said:

M$ office  not only causes a lot  of problems  with malware on Windows it's the #1 cause of malware on MAC OS  too.  I don't use M$ office at home  but some others on my network do is this not already been mitigated by Anti-malware?  :s

 

DEE Exploit via filehost  .exe  type spoted in the wild on Filefactroy


https://virustotal.com/en/file/316f0552684bd09310fc8a004991c9b7ac200fb2a9a0d34e59b8bbd30b6dc8ea/analysis/

Word DEE Exploit


https://www.virustotal.com/en/file/1a1294fce91af3f7e7691f8307d07aebd4636402e4e6a244faac5ac9b36f8428/analysis/

Yes it has to answer my own question . :dance2:

Yes and in fact i know a friend who has been infected badly on Mac os:yes:

Link to comment
Share on other sites


1 minute ago, hacker7 said:

Yes and in fact i know a friend who has been infected badly on Mac os:yes:

Here is   another  Office one  out in the wild .

 

DEE Exploit   Attacking Freddie Mac employees

https://www.virustotal.com/en/file/a335270704e339babeb19e81dccaf3dfa0808bdd4ae7f4b1a1ddbbd65f5e017d/analysis/

 

 

Link to comment
Share on other sites


9 hours ago, steven36 said:

 

 

DEE Exploit   Attacking Freddie Mac employees


https://www.virustotal.com/en/file/a335270704e339babeb19e81dccaf3dfa0808bdd4ae7f4b1a1ddbbd65f5e017d/analysis/

 

 

:o

Link to comment
Share on other sites


9 hours ago, steven36 said:

Chinese backdoor malware resurfaces after more than a decade

http://www.zdnet.com/article/chinese-backdoor-malware-resurfaces-after-more-than-a-decade/

 

Hackers Door  :dribble:

 

 

 

 

 

Quote

malware can grab screenshots and files, covertly download additional tools, and open telnet and remote access port. The tool can also extract Windows user's credential from the current session and grab system information.

 

Must say: sheers for Winnti. :dance:

 

Malware been ruining over a decade and they just found out about it !

 

Quote

The Motha F**ckas must be rich by now :tooth:

Link to comment
Share on other sites


tho they are not even sure about windows 10 yet :snack:

Link to comment
Share on other sites


9 hours ago, UmbraEmsisoft said:

AV's scanners may not catch this attack but their behavior blockers or HIPS will. 

Are U talking about the Unpatched Microsoft Word ? or the Winnti  Malware?

Link to comment
Share on other sites


UmbraEmsisoft
On 10/21/2017 at 4:23 PM, hacker7 said:

Are U talking about the Unpatched Microsoft Word ? or the Winnti  Malware?

the unpatched one. Didn't checked yet for the Winnti version.

Link to comment
Share on other sites


UmbraEmsisoft
6 hours ago, 0bin said:

Try the 64bit version of SimpleDNSCrypt, I had a performance improvement.

With 720 I am fine, there is not anymore the bug on scan with Hitman Pro that trigger the exploit alert in all previous ones.

well spotted for SimpleDNS crypt

 

For HMPA 720, try to run a backup with Windows Backup & Restore , and save it to another partition.

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...