Ponting Posted January 5, 2015 Share Posted January 5, 2015 Microsoft warns of increase in Adnel and Tarbir Trojan attacks on Excel and Word usersMicrosoft has warned its Microsoft Office users of significant rise in malware attacks through macros in Excel and Word programs. In a report published on its blog, Microsoft says that there is more than a threefold jump in the malware campaigns spreading two different Trojan downloaders. These Trojan downloaders arrive in emails masquerading as orders or invoices.The malwares are being spread through spam emails containing following subject lines accordingly to MicrosoftACH Transaction ReportDOC-file for report is readyInvoice as requestedInvoice – P97291Order – Y24383Payment DetailsRemittance Advice from Engineering Solutions LtdYour Automated Clearing House Transaction Has Been Put OnAnd the attachment containing Adnel and Tarbir campaigns is usually named as following :20140918_122519.doc813536MY.xlsACH Transfer 0084.docAutomated Clearing House transfer 4995.docBAC474047MZ.xlsBILLING DETAILS 4905.docCAR014 151239.docID_2542Z.xlsFuel bill.docORDER DETAILS 9650.docPayment Advice 593016.docSHIPPING DETAILS 1181.docSHIP INVOICE 1677.docSHIPPING NO.docMicrosoft Technet blog says that the two Trojan downloaders, TrojanDownloader:W97M/Adnel and TrojanDownloader:O97M/Tarbir are being spread at a rapid pace through spam emails and phishing campaigns. Worryingly they are targeting both home PC users and enterprise customers and most of the victims are based in United States and United Kingdom. As Microsoft has decided to block execution of Macros in Office by default, the trojan authors/handlers add a notification to the document stating the contents of the documents can only be viewed with macros enabled. Upon opening the malware laden Word document or Excel sheet, the victim receives a default security warning stating macros have been disabled but some users simply disregard this message and enable the macros thus allowing the trojan downloaders to infect their PCs.“The combination of the instructional document, spam email with supposed monetary content, and a seemingly relevant file name, can be enough to convince an unsuspecting user to click the Enable Content button”, according to Alden Pornasdoro of the MicrosoftMalware Protection Center.Once the Trojan downloader is downloaded it then starts to install other more deadlier malware on the systems it has infected.Microsoft says that majority of invoices and orders sent by users dont require macros however if a user comes across such an order or invoice, he/she should be selective in running such documents or sheets.Source: http://www.techworm.net/2015/01/microsoft-warns-new-malware-attacks-office-documents.html Link to comment Share on other sites More sharing options...
kantry123 Posted January 5, 2015 Share Posted January 5, 2015 SO whats the protection against this?EMET ?regards Link to comment Share on other sites More sharing options...
steven36 Posted January 5, 2015 Share Posted January 5, 2015 Microsoft security products, such as Microsoft Security Essentials, include detection for TrojanDownloader:W97M/Adnel and TrojanDownloader:O97M/Tarbir. To help stay protected we recommend you keep your security software up-to date.http://blogs.technet.com/b/mmpc/archive/2015/01/02/before-you-enable-those-macros.aspxMost anti malware programs should be able to detect it . Considering MSE is one the worse ones .Edit: Check this out seems if you run across TrojanDownloader:W97M/Adnel your safe with most good AVhttps://www.virustotal.com/en/file/1e0f0179fd559c96b5aa9b135a32a6527bdf81694f8b27599e5fb6d3c660ad94/analysis/But the other one it dont look like your protected with most TrojanDownloader:O97M/Tarbir.https://www.virustotal.com/en/file/a8ee9b6f3dfd02957d2f9f8abada269cbf7257a0d5745f2bae63c2a6892b83c5/analysis/ :ph34r: Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.