{"id":84751,"date":"2017-08-31T14:09:49","date_gmt":"2017-08-31T08:39:49","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=84751"},"modified":"2017-08-31T17:56:20","modified_gmt":"2017-08-31T12:26:20","slug":"malspam-campaign-using-cve-2017-0199-targets-manufacturing-pharmaceutical-important-industries","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/malspam-campaign-using-cve-2017-0199-targets-manufacturing-pharmaceutical-important-industries\/","title":{"rendered":"Malspam Campaign using CVE-2017-0199 Targets Manufacturing, Pharmaceutical, and other important Industries"},"content":{"rendered":"<p>Quick Heal Security Labs has come across various email campaigns that are actively exploiting the famous vulnerability <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-0199\">CVE-2017-0199<\/a> in their bid to target prominent private industries in India. CVE-2017-0199 was a zero-day vulnerability reported in April 2017 by two different security firms. Almost all of the MS Office versions were affected by it. Microsoft had issued a patch for this vulnerability on 11th April 2017. As usual, many attackers started exploiting this vulnerability in their spam campaigns.\u00a0 The following is an analysis of this campaign by Quick Heal Security Labs.<\/p>\n<p><strong>Attack chain<\/strong><\/p>\n<figure id=\"attachment_84752\" aria-describedby=\"caption-attachment-84752\" style=\"width: 2074px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-84752\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign1.jpg\" alt=\"Fig 1\" width=\"2074\" height=\"778\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign1.jpg 2074w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign1-300x113.jpg 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign1-768x288.jpg 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign1-650x244.jpg 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign1-789x296.jpg 789w\" sizes=\"(max-width: 2074px) 100vw, 2074px\" \/><figcaption id=\"caption-attachment-84752\" class=\"wp-caption-text\">Fig 1<\/figcaption><\/figure>\n<p><strong>Targeted organizations<br \/>\n<\/strong>The below figure represents the statistics of organizations targeted by the malicious campaign.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-84753\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign2.jpg\" alt=\"Fig 2\" width=\"1036\" height=\"449\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign2.jpg 1036w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign2-300x130.jpg 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign2-768x333.jpg 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign2-650x282.jpg 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/MalSpam-Campaign2-789x342.jpg 789w\" sizes=\"(max-width: 1036px) 100vw, 1036px\" \/><\/p>\n<p>The manufacturing sector seems to be the most favored target followed by pharmaceuticals, exports, and hotels.<\/p>\n<p><strong>Download the PDF report below to go through a detailed technical analysis of the campaign<\/strong><\/p>\n<p><a href=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/08\/An-analysis-of-the-CVE-2017-0199-MalSpam-Campaign-by-Quick-Heal-Security....pdf\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-84757\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/08\/pdf-icon-150x150.png\" alt=\"pdf-icon\" width=\"87\" height=\"87\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/pdf-icon-150x150.png 150w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/pdf-icon-70x70.png 70w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/pdf-icon-80x81.png 80w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/pdf-icon-45x45.png 45w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/08\/pdf-icon.png 256w\" sizes=\"(max-width: 87px) 100vw, 87px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Acknowledgment<\/strong><\/p>\n<p>Subject Matter Experts<\/p>\n<ul>\n<li>Pawan Chaudhari, Aniruddha Dolas | Quick Heal Security Labs<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Quick Heal Security Labs has come across various email campaigns that are actively exploiting the famous vulnerability CVE-2017-0199 in their bid to target prominent private industries in India. CVE-2017-0199 was a zero-day vulnerability reported in April 2017 by two different security firms. Almost all of the MS Office versions were affected by it. Microsoft had [&hellip;]<\/p>\n","protected":false},"author":29,"featured_media":84760,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[289,171,24,75],"tags":[],"class_list":["post-84751","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-safety","category-enterprise","category-malware","category-microsoft-windows"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84751"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=84751"}],"version-history":[{"count":5,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84751\/revisions"}],"predecessor-version":[{"id":84763,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84751\/revisions\/84763"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/84760"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=84751"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=84751"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=84751"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}