Advanced Word Document Infection
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Microsoft Word files loaded with scripts that launch exploits using embedded files is far from a new tactic. However the new malware campaign differs in a number of ways - it contains new anti-detection mechanisms and it can swap the final payload depending upon the vulnerabilities present on the user's system.
The final exploit payload is not embedded within the document but obtained via a Command and Control (C2) infrastructure. A complicated process unwraps various layers including functions later used which are hidden within the C2 and encrypted. This prevents detection by anti-virus software and also assists with reconnaissance to determine the type of attacks.
The document itself is a Rich Text Format (RTF) document with a number of embedded objects found within. The first is an Object Linking and Embedding (OLE) object that holds an Adobe Flash object. The Flash object extracts a second Flash object embedded within itself which is encoded using two different compression algorithms.
The second Flash object identifies the URL of the C2 infrastructure, miropc[.]org, and sends an HTTP request to the “/nato” directory in that URL. System information of the user's device is collected by flash.system.Capabilities.serverString which is usually used by legitimate Flash files to obtain the capabilities of the installed Adobe Flash version. This information allows the attacker to make decisions about whether to continue the attack and what type of attack will be effective.
Further HTTP requests are sent to different C2 URL directories which vary for each attack. An exchange of encrypted files delivers the encrypted payload which is decrypted and executed to compromise the machine. In some cases the payload is swapped and instead delivers a substantial amount of junk data designed to hamper the activities of security researchers.
Remediation steps
Last edited: 17 February 2020 11:25 am