preview

National University Threat Analysis Report Sample

Decent Essays

National University Threat Analysis Report The following report is a deep analysis the threat known as CVE-2017-11292; as mentioned in the previous threat analysis report summarizing three current threats. The purpose of the report is to notify National University of the harm that may be caused by CVE-2017-11292 and provide mitigations and solutions. CVE-2017-11292 Kaspersky has discovered on October 10, 2017, an Adobe Flash zero-day exploit. Adobe assigned it CVE-2017-11292. The payload is delivered, most commonly by a socially engineered email, through a Microsoft Office document. Embedded within the document is an ActiveX object which contains the Flash exploit as shown in the image below. (GReAT, 2017) The Flash object contains an ActionScript which is responsible for extracting the exploit using a custom packer. This custom packer has been seen in other FinSpy exploits, according to Kaspersky. The main exploit is a memory corruption vulnerability that is within the “com.adobe.tvsdk.mediacore.BufferControlParameters” class. If successful, attackers will gain read / write operations within memory; which is only stage one of the attack. …show more content…

Download FinSpy (mo.exe) 2. Download a lure document to display to the victim 3. Execute the payload and display the lure document Mo.exe is the newest version of Gamma International FinSpy malware which is normally sold to law enforcement for surveillance. “This newer variant has made it especially difficult for researchers to analyze the malware due to many added anti-analysis techniques, to include a custom packer and virtual machine to execute code. (GReAT, 2017)” Once the payload is started, it will copy files to these locations: • C:\ProgramData\ManagerApp\AdapterTroubleshooter.exe • C:\ProgramData\ManagerApp\15b937.cab •

Get Access