<!--DEBUG:--><!--DEBUG:dc3-united-states-software-in-english-pdf-2--><!--DEBUG:--><!--DEBUG:dc3-united-states-software-in-english-pdf-2--><!--DEBUG-spv-->{"id":1982688,"date":"2021-09-05T02:26:00","date_gmt":"2021-09-05T00:26:00","guid":{"rendered":"http:\/\/nhub.news\/?p=1982688"},"modified":"2021-09-05T05:05:58","modified_gmt":"2021-09-05T03:05:58","slug":"made-on-windows-11-alpha-themed-microsoft-word-documents-are-actually-malware-in-disguise","status":"publish","type":"post","link":"http:\/\/nhub.news\/fr\/2021\/09\/made-on-windows-11-alpha-themed-microsoft-word-documents-are-actually-malware-in-disguise\/","title":{"rendered":"&quot;Made on Windows 11 Alpha&quot;-themed Microsoft Word documents are actually malware in disguise"},"content":{"rendered":"<p style=\"text-align: justify;\"><b>\u00ab\u00a0Made on Windows 11 Alpha\u00a0\u00bb themed malicious Microsoft Word documents have been discovered by the security researchers at Anomali. The maldoc implements VBA macros to deliver a JavaScript payload.<\/b><br \/>\nAnomali Threat Research, a security research firm, has issued a warning about a malicious Microsoft Word document (maldoc), six of which have been discovered, that is masquerading as a document \u00ab\u00a0made on Windows 11 Alpha.\u00a0\u00bb The name of the file is \u00a0\u00bb Users-Progress-072021-1.doc \u00ab\u00a0. Most people familiar with the Windows 11 builds and their variations would probably be aware of such a thing never existing. However, people out of the loop may fall for this and decide to run the file as they might have heard all the commotion about the next-gen Windows OS. The maldoc uses VBA (Visual Basic for Application) macros to drop a JavaScript payload upon successful exploitation. The macro is executed when the user clicks on \u00ab\u00a0Enable editing\u00a0\u00bb and \u00ab\u00a0Enable content\u00a0\u00bb as instructed on the document&rsquo;s cover. There is a lot of junk data so as to make analysis difficult for researchers and cybercrime hunters but cleaning up much of it reveals how the threat actors wish to infect a system with this document. For example, there are several checks the maldoc performs, like: CLEARMIND is apparently the domain of a Point-of-Sale (POS) service provider for the retail and hospitality sector. Anomali believes this file has been created by the FIN7 group which is famous for striking such targets to steal large-scale data. More technical details on the maldoc can be found in the official blog post here.<\/p>\n<script>jQuery(function(){jQuery(\".vc_icon_element-icon\").css(\"top\", \"0px\");});<\/script><script>jQuery(function(){jQuery(\"#td_post_ranks\").css(\"height\", \"10px\");});<\/script><script>jQuery(function(){jQuery(\".td-post-content\").find(\"p\").find(\"img\").hide();});<\/script>","protected":false},"excerpt":{"rendered":"<p>\u00ab\u00a0Made on Windows 11 Alpha\u00a0\u00bb themed malicious Microsoft Word documents have been discovered by the security researchers at Anomali. The maldoc implements VBA macros to deliver a JavaScript payload. Anomali Threat Research, a security research firm, has issued a warning about a malicious Microsoft Word document (maldoc), six of which have been discovered, that is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1982687,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[93],"tags":[],"_links":{"self":[{"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/posts\/1982688"}],"collection":[{"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/comments?post=1982688"}],"version-history":[{"count":1,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/posts\/1982688\/revisions"}],"predecessor-version":[{"id":1982689,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/posts\/1982688\/revisions\/1982689"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/media\/1982687"}],"wp:attachment":[{"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/media?parent=1982688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/categories?post=1982688"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/nhub.news\/fr\/wp-json\/wp\/v2\/tags?post=1982688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}