This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • malware server and csvs/tsvs with DDE
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

malware server and csvs/tsvs with DDE

VladimirPrevin
VladimirPrevin Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-11-20 07:27 PM


a) It looks like Malware server does not process CSVs as a suspect filetype at all.
   a. As per this and these https://www.we45.com/2017/02/14/csv-injection-theres-devil-in-the-detail/ https://pentestmag.com/formula-injection/ https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSV%20injection https://www.contextis.com/blog/comma-separated-vulnerabilities http://www.exploresecurity.com/from-csv-to-cmd-to-qwerty/
   b. CSV/TSV files can quite clearly carry malicious content as far as excel is concerned.
b) (while I again want to point out RSA should be syncing this content via live (not 3m later in an RPM) to customers not us chasing you)
   a. we'd love to add a yara rules on malware for it but https://community.rsa.com/docs/DOC-78558
      i. (After a month the pictures still haven't been fixed) and
      ii. it seems like malware treats the file as none of these
         1. fileType Specifies the files type. Possible values are: WINDOWS_PE, MS_OFFICE, and PDF. If not specified, the default value is WINDOWS_PE.
   b. E.g.
      i. https://github.com/Neo23x0/signature-base/blob/master/yara/gen_dde_in_office_docs.yar https://github.com/InQuest/yara-rules/blob/master/Microsoft_Office_DDE_Command_Execution.rule
c) are we adding the yara rule incorrectly?
   a. or is this a product limitation?
   b. can it be addressed as a bug.
   c. These are exploited in the wild for about a month now. (Along with this https://community.rsa.com/message/900278?commentID=900278#comment-900278 )

  • Community Thread
  • csv
  • dde
  • Discussion
  • Forum Thread
  • NetWitness
  • NW
  • NWP
  • rsa malware server
  • RSA NetWitness
  • RSA NetWitness Platform
  • tsv
  • yara
0 Likes
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
0 REPLIES 0
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.