Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

BOLO: PowerPoint Order/Invoice Exploit

June 9, 2017 Jared Hall BOLOs, Microsoft Windows

This is another Office document infection that can occur without the benefit of Macros.   The active malware associated with this exploit is called “Zusy” and affects Microsoft PowerPoint.

The infection occurs when the mouse is moved over (Mouse-Over)  a warning hyperlink.  PowerPoint inexplicably invokes PowerShell, allowing the exploit to install.

When the user opens the file, a popup message appears that says, “Loading … Please Wait,”.  Moving the mouse over the popup message to check the hyperlink causes the Zusy infection; no clicking required!

However, the newest scam contains a hyperlink that, if hovered over, will trigger a command that infects the computer with the Zusy malware, no clicking required.  The Mouse-Over causes PowerShell to download the malicious JavaScript Executable (.jse)   That, in turn, downloads the Zusy payload.

Zusy is propagated by spam email and will include subject lines like “Purchase Order #” or “Confirmation“.   Those messages will have a  PowerPoint file attached that have a name like “order.ppsx”, “invoice.ppsx” or “order&prsn.ppsx”.

Again, people should exercise some common sense.  How many invoices or orders do you get via a PowerPoint presentation?  Infections will be more likely to occur in older versions of Office, like Office 2007.  An updated anti-virus/anti-malware program will likely stop this infection as well.

There is a good write-up on this malware at Kaspersky’s ThreatPost.

 

 

« Top Attacking Countries: May 2017 » A Funny Sign of Our Times

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017