New Exploits of LNK vulnerability in the Wild

Discussion in 'malware problems & news' started by Rmus, Aug 1, 2010.

Thread Status:
Not open for further replies.
  1. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    3,943
    Location:
    California
    I've found these descriptions of new exploits of the LNK vulnerability. Please post others as you find them.

    ZeuS/ZBOT and SALITY Jump on the LNK Exploit Bandwagon
    http://blog.trendmicro.com/zeuszbot-and-sality-jump-on-the-lnk-exploit-bandwagon/
    This one appears to be a retake on the old fake MS update emails. The difference here is that if the victim chooses to open the ZIP file, the LNK files will execute automatically.

    _______________________________________________________________​

    Downloader-CJX Cashing In on Microsoft .LNK Flaw
    http://www.avertlabs.com/research/blog/index.php/category/exploit-research/
    This one appears to require both malware to install the malicious LNK files, and some social engineering.

    _______________________________________________________________​



    ----
    rich
     
    Last edited: Aug 2, 2010
  2. dlimanov

    dlimanov Registered Member

    Joined:
    Jun 10, 2009
    Posts:
    204
  3. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    3,943
    Location:
    California
    I'd prefer to keep this thread about the new exploits.

    Protection/detection are discussed in other threads.

    thanks,

    rich
     
  4. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,833
  5. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    3,943
    Location:
    California
    http://www.f-secure.com/weblog/archives/00001996.html

    Thanks - I see it's one of the fake MS update emails:

    This is funny in a sense, because the PoC that everyone was testing had the user copy the DLL to C: and I said that exploits in the Wild don't work that way.

    Well, here is one that does! Do you suppose the creators of this fake MS update were influenced by the PoC?

    ----
    rich
     
  6. ParadigmShift

    ParadigmShift Registered Member

    Joined:
    Aug 7, 2008
    Posts:
    203
    Probably, but I think they lurk here as well.
     
Loading...
Thread Status:
Not open for further replies.