Targeted Attacks Against Japanese Firm Use Old ActiveX Vulnerability

The instigators of many targeted attacks are fond of using the CVE-2012-0158  vulnerability, which affects mscomctl.ocx in Microsoft Office and some other Microsoft products. We have seen several campaigns using this exploit against Chinese and Tibetian activists and in other recent attacks. Now McAfee Labs has uncovered another apparent targeted attack using the same vulnerability against a Japanese firm.

In the recent wave of the attacks using this exploit, the potential target seems to be the Japan Aerospace Exploration Agency (JAXA). We have found Word .doc exploits taking advantage of CVE-2012-0158 with the decoy document contents related to JAXA.

We first saw exploit-laden doc files in the wild on April 7 with the following file name: 

EOC運営調整会議議事録(最終版).doc. Rough translation: “EOC management coordination meeting minutes (final version)”

Author: RESTEC観測部. “RESTEC observation section”

Title: ALOS地球観測班準備連絡会 議事録. “ALOS Earth observation team preparation Liaison Committee meeting minutes”

Threat Vector

The threat arrives in a Word doc file that exploits the CVE-2012-0158 vulnerability in the mscomctl.ocx ActiveX control. Opening the doc exploit opens another decoy document and drops a binary, services.exe, in the %Temp% directory. This binary copies itself into C:\Program Files\Windows NT\Accessories\Microsoft and runs from there.

Analyzing the payload

Network communication

The following are additional malware we’ve seen communicating with the same domain:



McAfee detection: 

McAfee Advanced Threat Detection provides zero-day detection against this exploit based on its behaviour analysis. As always, we advise users to consider carefully before opening documents from unknown sources.

