* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, November 19, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

    Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

    Claire Danes Gets Honest About Her Surprise Pregnancy at Age 44 – Yahoo

    Claire Danes Gets Honest About Her Surprise Pregnancy at Age 44 – Yahoo

    The next Met Gala exhibit will spotlight fashion across art history – San Francisco Chronicle

    The next Met Gala exhibit will spotlight fashion across art history – San Francisco Chronicle

    The Running Man to David Hockney: your complete entertainment guide to the week ahead | Culture – The Guardian

    The Running Man to David Hockney: your complete entertainment guide to the week ahead | Culture – The Guardian

    Kelly Brook opens up on ‘horrific’ miscarriage that left her never wanting to try for a baby again – Woman & Home

    Kelly Brook opens up on ‘horrific’ miscarriage that left her never wanting to try for a baby again – Woman & Home

    Bartlett Police investigating shooting at kids entertainment center, officials say – FOX13 Memphis

    Shooting at Kids Entertainment Center Under Investigation by Bartlett Police

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Mid-Atlantic Technology Summit 2025 showcases next-gen tools for first responders – FireRescue1

    Mid-Atlantic Technology Summit 2025 Reveals Game-Changing Tools Empowering First Responders

    CFCC to host career discovery nights on K-12 Teacher Preparation and Chemical Technology programs – WECT

    Unlock Your Potential: Career Discovery Nights for K-12 Teacher Preparation and Chemical Technology Programs at CFCC

    Continental Uses Vacuum Technology to Study Tire Wear Particles – Continental AG

    Continental Uses Vacuum Technology to Study Tire Wear Particles – Continental AG

    Apply Now: $50,000 for AI-Powered Financial Technology Solutions – ICTworks

    Secure $50,000 to Fuel Your Groundbreaking AI-Powered FinTech Innovation – Apply Now!

    Award-Winning Pet Brand Enters Self-Cleaning Litter Box Market With Latest Innovation – ParadePets

    Revolutionary Innovation Transforms Self-Cleaning Litter Boxes by Award-Winning Pet Brand

    Girls Exploring Tomorrow’s Technology marks 25th anniversary – pottsmerc.com

    Celebrating 25 Years of Inspiring Girls to Explore Tomorrow’s Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

    Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

    Claire Danes Gets Honest About Her Surprise Pregnancy at Age 44 – Yahoo

    Claire Danes Gets Honest About Her Surprise Pregnancy at Age 44 – Yahoo

    The next Met Gala exhibit will spotlight fashion across art history – San Francisco Chronicle

    The next Met Gala exhibit will spotlight fashion across art history – San Francisco Chronicle

    The Running Man to David Hockney: your complete entertainment guide to the week ahead | Culture – The Guardian

    The Running Man to David Hockney: your complete entertainment guide to the week ahead | Culture – The Guardian

    Kelly Brook opens up on ‘horrific’ miscarriage that left her never wanting to try for a baby again – Woman & Home

    Kelly Brook opens up on ‘horrific’ miscarriage that left her never wanting to try for a baby again – Woman & Home

    Bartlett Police investigating shooting at kids entertainment center, officials say – FOX13 Memphis

    Shooting at Kids Entertainment Center Under Investigation by Bartlett Police

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Mid-Atlantic Technology Summit 2025 showcases next-gen tools for first responders – FireRescue1

    Mid-Atlantic Technology Summit 2025 Reveals Game-Changing Tools Empowering First Responders

    CFCC to host career discovery nights on K-12 Teacher Preparation and Chemical Technology programs – WECT

    Unlock Your Potential: Career Discovery Nights for K-12 Teacher Preparation and Chemical Technology Programs at CFCC

    Continental Uses Vacuum Technology to Study Tire Wear Particles – Continental AG

    Continental Uses Vacuum Technology to Study Tire Wear Particles – Continental AG

    Apply Now: $50,000 for AI-Powered Financial Technology Solutions – ICTworks

    Secure $50,000 to Fuel Your Groundbreaking AI-Powered FinTech Innovation – Apply Now!

    Award-Winning Pet Brand Enters Self-Cleaning Litter Box Market With Latest Innovation – ParadePets

    Revolutionary Innovation Transforms Self-Cleaning Litter Boxes by Award-Winning Pet Brand

    Girls Exploring Tomorrow’s Technology marks 25th anniversary – pottsmerc.com

    Celebrating 25 Years of Inspiring Girls to Explore Tomorrow’s Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

New attack uses MSC files and Windows XSS flaw to breach networks

June 25, 2024
in Technology
New attack uses MSC files and Windows XSS flaw to breach networks
Share on FacebookShare on Twitter

Windows

A novel command execution technique dubbed ‘GrimResource’ uses specially crafted MSC (Microsoft Saved Console) and an unpatched Windows XSS flaw to perform code execution via the Microsoft Management Console.

In July 2022, Microsoft disabled macros by default in Office, causing threat actors to experiment with new file types in phishing attacks. The attackers first switched to ISO images and password-protected ZIP files, as the file types did not properly propagate Mark of the Web (MoTW) flags to extracted files.

After Microsoft fixed this issue in ISO files and 7-Zip added the option to propagate MoTW flags, attackers were forced to switch to new attachments, such as Windows Shortcuts and OneNote files.

Attackers have now switched to a new file type, Windows MSC (.msc) files, which are used in the Microsoft Management Console (MMC) to manage various aspects of the operating system or create custom views of commonly accessed tools.

The abuse of MSC files to deploy malware was previously reported by South Korean cybersecurity firm Genian. Motivated by this research, the Elastic team discovered a new technique of distributing MSC files and abusing an old but unpatched Windows XSS flaw in apds.dll to deploy Cobalt Strike.

Elastic found a sample (‘sccm-updater.msc’) recently uploaded onto VirusTotal on June 6, 2024, which leverages GrimResource, so the technique is actively exploited in the wild. To make matters worse, no antivirus engines on VirusTotal flagged it as malicious.

While this campaign is using the technique to deploy Cobalt Strike for initial access to networks, it could also be used to execute other commands.

The researchers confirmed to Bleepingcomputer that the XSS flaw is still unpatched in the latest version of Windows 11.

How GrimResource works

The GrimResource attack begins with a malicious MSC file that attempts to exploit an old DOM-based cross-site scripting (XSS) flaw in the ‘apds.dll’ library, which allows the execution of arbitrary JavaScript through a crafted URL.

The vulnerability was reported to Adobe and Microsoft in October 2018, and while both investigated, Microsoft determined that the case did not meet the criteria for immediate fixing.

As of March 2019, the XSS flaw remained unpatched, and it is unclear if it was ever addressed. BleepingComputer contacted Microsoft to confirm if they patched the flaw, but a comment wasn’t immediately available.

The malicious MSC file distributed by attackers contains a reference to the vulnerable APDS resource in the StringTable section, so when the target opens it, MMC processes it and triggers the JS execution in the context of ‘mmc.exe.’

Reference to apds.dll redirect in StringTableReference to apds.dll redirect in StringTable
Source: Elastic Security

Elastic explains that the XSS flaw can be combined with the ‘DotNetToJScript’ technique to execute arbitrary .NET code through the JavaScript engine, bypassing any security measures in place.

The examined sample uses ‘transformNode’ obfuscation to evade ActiveX warnings, while the JS code reconstructs a VBScript that uses DotNetToJScript to load a .NET component named ‘PASTALOADER.’

The malicious VBScript fileThe malicious VBScript file
Source: Elastic Security

PASTALOADER retrieves a Cobalt Strike payload from the environment variables set by the VBScript, spawns a new instance of ‘dllhost.exe,’ and injects it using the ‘DirtyCLR’ technique combined with function unhooking and indirect system calls.

Cobalt Strike injected into dllhost.exeCobalt Strike injected into dllhost.exe
Source: Elastic Security

Elastic researcher Samir Bousseaden shared a demonstration of the the GrimResource attack on X.

Demonstration of the GrimResource attack
Demonstration of the GrimResource attack

Stopping GrimResource

In general, system administrators are advised to be on the lookout for the following:

File operations involving apds.dll invoked by mmc.exe.
Suspicious executions via MCC, especially processes spawned by mmc.exe with .msc file arguments.
RWX memory allocations by mmc.exe that originate from script engines or .NET components.
Unusual .NET COM object creation within non-standard script interpreters like JScript or VBScript.
Temporary HTML files created in the INetCache folder as a result of APDS XSS redirection.

Elastic Security has also published a complete list of GrimResource indicators on GitHub and provided YARA rules in the report to help defenders detect suspicious MSC files.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/new-grimresource-attack-uses-msc-files-and-windows-xss-flaw-to-breach-networks/

Tags: AttackFilestechnology
Previous Post

Indiana Women’s Basketball Coach Teri Moren Wins Gold Medal With USA U18 Team

Next Post

Chrome for Android tests feature that securely verifies your ID with sites

Putative ‘Dispersal Adaptations’ Do Not Explain the Colonisation of a Volcanic Island by Vascular Plants, but Birds Can – Wiley Online Library

Why Birds, Not Dispersal Adaptations, Drive Vascular Plant Colonization on Volcanic Islands

November 19, 2025
NVIDIA Accelerates AI for Over 80 New Science Systems Worldwide – NVIDIA Blog

NVIDIA Drives AI Innovation with Over 80 Cutting-Edge Scientific Systems Worldwide

November 19, 2025
Neanderthals and early humans ‘likely to have kissed’, say scientists – The Guardian

Did Neanderthals and Early Humans Share a Kiss? Scientists Say It’s Likely Could Neanderthals and Early Humans Have Shared a Kiss? New Research Suggests They Probably Did

November 19, 2025
People who stay genuinely happy after 50 usually practice these 7 daily rituals – VegOut

7 Daily Habits That Unlock Lasting Happiness After 50

November 19, 2025
Mid-Atlantic Technology Summit 2025 showcases next-gen tools for first responders – FireRescue1

Mid-Atlantic Technology Summit 2025 Reveals Game-Changing Tools Empowering First Responders

November 19, 2025
NFL Injury Report: Tracking latest news, updates on Josh Jacobs, Drake London and more for fantasy football in Week 12 – Yahoo Sports

Week 12 Fantasy Football Injury Update: Crucial News on Josh Jacobs, Drake London, and More

November 19, 2025
Scotland vs. Denmark: Livestream World Cup 2026 Qualifier Soccer From Anywhere – CNET

Scotland vs. Denmark: Livestream World Cup 2026 Qualifier Soccer From Anywhere – CNET

November 19, 2025
Tomorrow.Blue Economy explored the potential of the blue economy for ports, cities and corporations – Yahoo Finance

Unlocking the Future: How the Blue Economy Will Revolutionize Ports, Cities, and Corporations

November 19, 2025
Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

November 19, 2025
Boat Electrification Is a Climate and Health Win. Making the Switch Isn’t Easy. – Inside Climate News

How Electrifying Boats Can Boost Climate and Health-And Why the Transition Is Challenging

November 19, 2025

Categories

Archives

November 2025
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
« Oct    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (926)
  • Economy (945)
  • Entertainment (21,820)
  • General (18,262)
  • Health (9,985)
  • Lifestyle (957)
  • News (22,149)
  • People (950)
  • Politics (958)
  • Science (16,159)
  • Sports (21,446)
  • Technology (15,926)
  • World (932)

Recent News

Putative ‘Dispersal Adaptations’ Do Not Explain the Colonisation of a Volcanic Island by Vascular Plants, but Birds Can – Wiley Online Library

Why Birds, Not Dispersal Adaptations, Drive Vascular Plant Colonization on Volcanic Islands

November 19, 2025
NVIDIA Accelerates AI for Over 80 New Science Systems Worldwide – NVIDIA Blog

NVIDIA Drives AI Innovation with Over 80 Cutting-Edge Scientific Systems Worldwide

November 19, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version