Less than 15 days after the release of Oracle Java CPU Special Update of 19 February, another Java 0day is reported exploited in the wild !
FireEye has report, in a blog post, the discovery of a new Oracle Java 0day targeting latest versions JSE 6 Update 41 and JSE 7 Update 15.
After successful exploitation of the newly discovered vulnerability, CVE-2013-1493, “svchost.jpg” (b6c8ede9e2153f2a1e650dfa05b59b99) file is loaded from the same server hosting the Java 0day. Then McRAT (aka Trojan.Naid) malware (4d519bf53a8217adc4c15d15f0815993) is dropped. Regarding the detection ratio of this malware (21/46), it seem that the Java 0day could be used in Exploit Pack.
- VirusTotal analysis of dropped McRAT.
- Malwr analysis of dropped McRAT.
- Anubis analysis of dropped McRAT.
Symantec has report some connections through the new Oracle Java 0day with the Bit9 security incident. In the actual Java 0day security incident case, “appmgmt.dll” file, dropped by “svchost.jpg“, is detected by Symantec as Trojan.Naid. Trojan.Naid sample is connecting 110.173.55.187 C&C server. In the Bit9 security incident case, Trojan.Naid was also present and also connecting to 110.173.55.187 C&C server. Symantec detect this Java 0day as “Trojan.Maljava.B” and regarding associated threat assessment, less than 49 computers were infected and less than 2 websites were used in the watering hole attack.
Some security researchers are actually studying the sample, it is question of days before this 0day will be widely exploited.
We advise you to deactivate Java plug-in execution asap.
Update 2013-03-07:
Samples are appearing on VirusTotal like “svchost.jar” (a721ca9b2ea1c362bd704b57d4d5a280) with an actual detection ratio of 17/46.
CVE-2013-1493 aka Yet Another Oracle Java 0day http://t.co/gWntNEtxZV
CVE-2013-1493 aka Yet Another #Oracle #Java 0day http://t.co/I1TToTXjcY #security #javaniceday
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
CVE-2013-1493 aka YAJ0 http://t.co/ri9qLQNU7I
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
RT @virusbtn: Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n …
Something you don’t want to learn on a Friday: yet another Java zero-day discovered http://t.co/s2LalwLAKj http://t.co/m0n2iGfytL
CVE-2013-1493 aka Yet Another Oracle Java 0day http://t.co/SP1T7r9UYH
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
CVE-2013-1493 aka Yet Another Oracle Java 0day http://t.co/f0xAfsXR9l
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
CVE-2013-1493 aka Yet Another Oracle Java 0day http://t.co/ONmyUtfBiE
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/rZ5WpnioXu #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
RT @eromang: CVE-2013-1493 aka Yet Another #Oracle #Java #0day http://t.co/LqQoaMloba #infosec
CVE-2013-1493 aka Yet Another Oracle #Java #0day #HappyWeekend http://t.co/BkWoCcVTYV