3 ms·
Background on the advisory: http://krebsonsecurity.com/2011/04/new-adobe-flash-zero-day-being-exploited/ http://krebsonsecurity.com/2011/04/new-adobe-flash-zero
by trotsky 15y ago
Background on the advisory: http://krebsonsecurity.com/2011/04/new-adobe-flash-zero-day-being-exploited/ http://krebsonsecurity.com/2011/04/new-adobe-flash-zero-day-...
According to sources, the attacks exploit a vulnerability in fully-patched versions of Flash, and are being leveraged in targeted spear-phishing campaigns launched against select organizations and individuals that work with or for the U.S. government. Sources say the attacks so far have embedded the Flash exploit inside of Microsoft Word files made to look like important government documents.
Here's a virustotal scan of one of the documents: http://www.virustotal.com/file-scan/report.html?id=1e677420d7a8160c92b2f44f1ef5eea1cf9b0b1a25353db7d3142b268893507f-1302359653 http://www.virustotal.com/file-scan/report.html?id=1e677420d...
The fact that one AV engine detected it as a 0-day was the source of admonishments or congratulations depending on where the observers stood. Until it was discussed that the one detection was probably an unrelated false positive.
~~~
Additional artifacts from the attack including the spearphising tease and the times they were being sent (early morning friday apr 8) - at the height of the budget battle.
http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611...