Blog

NSS Labs’ CAWS has been monitoring the activity of CVE-2017-0199, which was patched by Microsoft on April 11, 2017. According to Microsoft, CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and WordPad. This vulnerability was initially exploited in a zero-day targeted attack. However, once the vulnerability was disclosed publicly, it was just a matter of days before it was utilized in a mass malware campaign.

NSS Labs can confirm that it has begun to see this vulnerability being actively exploited to distribute a Dridex variant. Recently, one of NSS Labs’ CAWS customers submitted a suspicious file that was found to be leveraging CVE-2017-0199.

The exploit relies heavily on PowerShell to disable several add-on features in MS Word by deleting the key HKCU\Software\Microsoft\Office\14.0\Word\Resiliency.

The exploit also launches a decoy document to give the impression that nothing unusual has occurred. Once the vulnerability has been exploited, it connects to a remote domain to obtain the Dridex variant. The Dridex variant contacts three IP addresses over TCP port 4743.

At this time, VirusTotal is reporting: https://virustotal.com/en/file/d1d3d00e0897bad3b57415b3a233fb328cf3d195c4406882f25436f7e14ecc9e/analysis/

The CAWS Cyber Threat Protection Platform continuously analyzes and validates the modus operandi of active exploits in the wild, along with the specific applications being targeted, and the effectiveness of an organization’s security controls to defend against them. The result is preemptive, contextual threat intelligence that enables organizations to stay ahead of breaches, including zero-day attacks.

INDICATORS OF COMPROMISE (IOCS)

  • rottastics36w.net
  • 199.36.194.27
  • 104.131.182.74
  • 199.233.245.109
  • 8B6F6BDEFDC6B42ABF9F372123152AB2
  • 3FF4C0FC7935514C4374ECA57BF2C019