Jump to content

Microsoft warns for new malware attacks with Office documents


Ponting

Recommended Posts

url.png




Microsoft warns of increase in Adnel and Tarbir Trojan attacks on Excel and Word users

Microsoft has warned its Microsoft Office users of significant rise in malware attacks through macros in Excel and Word programs. In a report published on its blog, Microsoft says that there is more than a threefold jump in the malware campaigns spreading two different Trojan downloaders. These Trojan downloaders arrive in emails masquerading as orders or invoices.
The malwares are being spread through spam emails containing following subject lines accordingly to Microsoft

  • ACH Transaction Report
  • DOC-file for report is ready
  • Invoice as requested
  • Invoice – P97291
  • Order – Y24383
  • Payment Details
  • Remittance Advice from Engineering Solutions Ltd
  • Your Automated Clearing House Transaction Has Been Put On

And the attachment containing Adnel and Tarbir campaigns is usually named as following :

  • 20140918_122519.doc
  • 813536MY.xls
  • ACH Transfer 0084.doc
  • Automated Clearing House transfer 4995.doc
  • BAC474047MZ.xls
  • BILLING DETAILS 4905.doc
  • CAR014 151239.doc
  • ID_2542Z.xls
  • Fuel bill.doc
  • ORDER DETAILS 9650.doc
  • Payment Advice 593016.doc
  • SHIPPING DETAILS 1181.doc
  • SHIP INVOICE 1677.doc
  • SHIPPING NO.doc

Microsoft Technet blog says that the two Trojan downloaders, TrojanDownloader:W97M/Adnel and TrojanDownloader:O97M/Tarbir are being spread at a rapid pace through spam emails and phishing campaigns. Worryingly they are targeting both home PC users and enterprise customers and most of the victims are based in United States and United Kingdom.

adnel1.png


As Microsoft has decided to block execution of Macros in Office by default, the trojan authors/handlers add a notification to the document stating the contents of the documents can only be viewed with macros enabled. Upon opening the malware laden Word document or Excel sheet, the victim receives a default security warning stating macros have been disabled but some users simply disregard this message and enable the macros thus allowing the trojan downloaders to infect their PCs.

“The combination of the instructional document, spam email with supposed monetary content, and a seemingly relevant file name, can be enough to convince an unsuspecting user to click the Enable Content button”, according to Alden Pornasdoro of the Microsoft
Malware Protection Center.

Once the Trojan downloader is downloaded it then starts to install other more deadlier malware on the systems it has infected.

Microsoft says that majority of invoices and orders sent by users dont require macros however if a user comes across such an order or invoice, he/she should be selective in running such documents or sheets.

Source: http://www.techworm.net/2015/01/microsoft-warns-new-malware-attacks-office-documents.html

Link to comment
Share on other sites


  • Replies 2
  • Views 1.5k
  • Created
  • Last Reply

SO whats the protection against this?

EMET ?

regards

Link to comment
Share on other sites


Microsoft security products, such as Microsoft Security Essentials, include detection for TrojanDownloader:W97M/Adnel and TrojanDownloader:O97M/Tarbir. To help stay protected we recommend you keep your security software up-to date.

http://blogs.technet.com/b/mmpc/archive/2015/01/02/before-you-enable-those-macros.aspx

Most anti malware programs should be able to detect it . Considering MSE is one the worse ones .

Edit: Check this out seems if you run across TrojanDownloader:W97M/Adnel your safe with most good AV

https://www.virustotal.com/en/file/1e0f0179fd559c96b5aa9b135a32a6527bdf81694f8b27599e5fb6d3c660ad94/analysis/

But the other one it dont look like your protected with most TrojanDownloader:O97M/Tarbir.

https://www.virustotal.com/en/file/a8ee9b6f3dfd02957d2f9f8abada269cbf7257a0d5745f2bae63c2a6892b83c5/analysis/

:ph34r:

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...