{"id":4506,"date":"2023-03-19T17:54:07","date_gmt":"2023-03-19T16:54:07","guid":{"rendered":"https:\/\/sajberinfo.com\/?p=4506"},"modified":"2023-03-19T17:54:07","modified_gmt":"2023-03-19T16:54:07","slug":"emotet-sada-koristi-microsoft-onenote-priloge","status":"publish","type":"post","link":"https:\/\/sajberinfo.com\/en\/2023\/03\/19\/emotet-sada-koristi-microsoft-onenote-priloge\/","title":{"rendered":"Emotet sada koristi Microsoft OneNote priloge"},"content":{"rendered":"<p><span style=\"font-size: 14pt;\"><em>Emotet<\/em> sada koristi <em>Microsoft<\/em> <em>OneNote<\/em> priloge kako bi zaobi\u0161ao sigurnosne mjere za\u0161tite i inficirao vi\u0161e korisnika.<\/span><\/p>\n<div id=\"attachment_4508\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4508\" class=\"size-full wp-image-4508\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-sada-koristi.jpg\" alt=\"Emotet sada koristi\" width=\"1024\" height=\"665\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-sada-koristi.jpg 1024w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-sada-koristi-300x195.jpg 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-sada-koristi-768x499.jpg 768w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-sada-koristi-18x12.jpg 18w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-4508\" class=\"wp-caption-text\"><em>Emotet sada koristi Microsoft OneNote priloge; Dizajn: Sa\u0161a \u0110uri\u0107<\/em><\/p><\/div>\n<h2><span style=\"font-size: 14pt;\"><strong>Stara taktika<\/strong><\/span><\/h2>\n<p><span style=\"font-size: 14pt;\"><em>Emotet<\/em> je ozlogla\u0161eni <a href=\"https:\/\/sajberinfo.com\/en\/2021\/09\/26\/malware\/\" target=\"_blank\" rel=\"nofollow noopener\">zlonamjerni softver<\/a> koji se u pro\u0161losti \u0161irio preko <em>Microsoft<\/em> <em>Word<\/em> i <em>Excel<\/em> priloga koji sadr\u017ee zlonamjerne <em>macro<\/em> skripte. Ako korisnik otvori prilog i omogu\u0107i <em>macro<\/em> skripte, dolazi do preuzimanja <em>DLL<\/em> datoteke koja instalira <em>Emotet<\/em> zlonamjerni softver na ure\u0111aj. Ovaj pristup se koristi za sprovo\u0111enje sajber napada na organizacije, koji mogu uklju\u010divati napade <em>ransomvare<\/em>-a, kra\u0111u podataka, sajber \u0161pijuna\u017eu i iznude.<\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Iako jedan od najrasprostranjenijih zlonamjernih softvera u pro\u0161losti, ulazi u fazu primjetnog usporavanja kampanja tokom pro\u0161le godine, da bi se naglo zaustavio krajem 2022. godine i napravio pauzu. Nakon ne\u0161to oko tri mjeseca neaktivnosti, <em>Emotet<\/em> <em>\u00a0<\/em>se iznenada <a href=\"https:\/\/sajberinfo.com\/en\/2023\/03\/14\/emotet-prvi-talas-u-2023-godini\/\" target=\"_blank\" rel=\"nofollow noopener\">ponovo aktivira ranije ovog mjeseca<\/a>.<\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Nova kampanje je bila malo \u010dudna, po\u0161to je koristila <em>Microsoft<\/em> <em>Word<\/em> i <em>Excel<\/em> priloge koji sadr\u017ee zlonamjerne <em>macro<\/em> skripte, skripte \u010diju je upotrebu kompanija <em>Microsoft<\/em> automatski blokirala u dokumentima preuzetim sa Interneta. O\u010dekivani uticaj ove kampanje na korisnike je bio veoma mali. Zbog ovoga, bilo je realno predvi\u0111anje da \u0107e zlonamjerni akteri promijeniti taktiku napada kako bi pro\u0161irili uticaj svoje kampanje na \u0161to ve\u0107i broj korisnika.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-size: 14pt;\"><strong>Promjena taktike<\/strong><\/span><\/h3>\n<p><span style=\"font-size: 14pt;\">Kao \u0161to je predvi\u0111eno, u <em>Emotet<\/em> zlonamjernoj kampanji dolazi do promjene koju je prvi primijetio sigurnosni istra\u017eiva\u010d <a href=\"https:\/\/twitter.com\/abel1ma\" target=\"_blank\" rel=\"noopener\"><em>Abel<\/em><\/a><em>.<\/em> Zlonamjerni akteri sada distribuiraju <em>Emotet<\/em> koriste\u0107i zlonamjerne <em>Microsoft<\/em> <em>OneNote<\/em> priloge. Ovi prilozi se distribuiraju u porukama elektronske po\u0161te u lancu odgovora koji imitiraju vodi\u010de, uputstva, fakture, reference za posao i sli\u010dno.<\/span><\/p>\n<div id=\"attachment_4509\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4509\" class=\"size-full wp-image-4509\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/document-is-protected.webp\" alt=\"document is protected\" width=\"1024\" height=\"620\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/document-is-protected.webp 1024w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/document-is-protected-300x182.webp 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/document-is-protected-768x465.webp 768w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/document-is-protected-18x12.webp 18w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-4509\" class=\"wp-caption-text\"><em>Malicious Microsoft OneNote attachment; Source: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/emotet-malware-now-distributed-in-microsoft-onenote-files-to-evade-defenses\/\" target=\"_blank\" rel=\"noopener\">BleepingComputer<\/a><\/em><\/p><\/div>\n<p><span style=\"font-size: 14pt;\">U prilogu elektronske po\u0161te <em>Microsoft<\/em> <em>OneNote<\/em> prikazuju poruku u kojoj se navodi da je dokument za\u0161ti\u0107en. Zatim se od korisnika tra\u017ei da dvaput kliknete na dugme \u201e<em>View<\/em>\u201c da biste ispravno prikazali dokument. Korisnik klikom aktivira <em>VBScript<\/em> datoteku pod nazivom \u201c<em>click.wsf<\/em>\u201d koja sadr\u017ei zamagljeni k\u00f4d za preuzimanje <em>DLL<\/em> datoteke sa udaljene kompromitovane Internet lokacije i njeno pokretanje.<\/span><\/p>\n<div id=\"attachment_4511\" style=\"width: 569px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4511\" class=\"size-full wp-image-4511\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Warning-when-opening-a-file.webp\" alt=\"Warning when opening a file\" width=\"559\" height=\"270\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Warning-when-opening-a-file.webp 559w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Warning-when-opening-a-file-300x145.webp 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Warning-when-opening-a-file-18x9.webp 18w\" sizes=\"auto, (max-width: 559px) 100vw, 559px\" \/><p id=\"caption-attachment-4511\" class=\"wp-caption-text\"><em>Warning when opening a file embedded in Microsoft OneNote; Source: <\/em><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/emotet-malware-now-distributed-in-microsoft-onenote-files-to-evade-defenses\/\" target=\"_blank\" rel=\"noopener\"><em>BleepingComputer<\/em><\/a><\/p><\/div>\n<h4><span style=\"font-size: 14pt;\"><strong>Preuzimanje zlonamjernog softvera<\/strong><\/span><\/h4>\n<p><span style=\"font-size: 14pt;\"><em>Microsoft<\/em> <em>OneNote<\/em> \u0107e u sklopu svoji bezbjednosnih mjera prikazati korisniku upozorenje kada korisnik poku\u0161a da pokrene ugra\u0111enu datoteku, ali pona\u0161anja korisnika iz pro\u0161losti pokazuju da mnogi korisnici obi\u010dno kliknu na dugme \u201c<em>OK<\/em>\u201d da bi se otarasili upozorenja. Nakon ignorisanja upozorenja, dolazi do pokretanja izvr\u0161ne datoteke <em>Wscript.exe<\/em> koja preuzima <em>Emotet <\/em>zlonamjerni softver i pokre\u0107e ga pod nasumi\u010dnim imenom koriste\u0107i <em>regsvr32<\/em>.<em>exe<\/em> datoteku.<\/span><\/p>\n<div id=\"attachment_4510\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4510\" class=\"size-full wp-image-4510\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-OneNote-proces.webp\" alt=\"Emotet OneNote proces\" width=\"1024\" height=\"664\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-OneNote-proces.webp 1024w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-OneNote-proces-300x195.webp 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-OneNote-proces-768x498.webp 768w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/03\/Emotet-OneNote-proces-18x12.webp 18w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-4510\" class=\"wp-caption-text\"><em>Emotet OneNote proces infekcije; Dizajn: Sa\u0161a \u0110uri\u0107<\/em><\/p><\/div>\n<p><span style=\"font-size: 14pt;\">Nakon svih ovih koraka, <em>Emotet <\/em>zlonamjerni softver \u0107e sada tiho raditi na ure\u0111aju korisnika i \u010dekati dalje naredbe od komandnog servera. Iako jo\u0161 uvije nije poznato koji softver se na kraju isporu\u010duje, obi\u010dno je u pitanju <em>Cobalt Strike<\/em> ili sli\u010dan zlonamjerni softver. Ovo omogu\u0107ava raznim zlonamjernim akterima da u saradnji sa upravlja\u010dima\u00a0 <em>Emotet <\/em>kampanje dobiju upori\u0161te na korisni\u010dkim ure\u0111ajima koje \u0107e poslije koristiti kao odsko\u010dnu dasku za dalje \u0161irenje.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h5><span style=\"font-size: 14pt;\"><strong>Blokiranje zlonamjernih Microsoft OneNote priloga<\/strong><\/span><\/h5>\n<p><span style=\"font-size: 14pt;\"><em>Microsoft<\/em> <em>OneNote<\/em> postaje ogroman problem u smislu distribucije zlonamjernog softvera, po\u0161to se koristi u sve vi\u0161e zlonamjernih kampanja. Zbog toga je kompanija <em>Microsoft<\/em> najavila implementaciju novi mehanizama za\u0161tite, me\u0111utim za sada ne postoji odre\u0111eni vremenski okvir kada \u0107e to biti dostupno korisnicima.<\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Bez obzira na to, administratori mogu da konfiguri\u0161u grupne polise kao bi se za\u0161titili od ovih prijetnji. Administratori kroz grupne polise imaju mogu\u0107nost da u potpunosti blokiraju ugra\u0111ene datoteke ili da defini\u0161u odre\u0111ene ekstenzije datoteke koje bi bile blokirane za pokretanje. Vi\u0161e informacija kako to uraditi mo\u017eete na\u0107i <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/how-to-prevent-microsoft-onenote-files-from-infecting-windows-with-malware\/\" target=\"_blank\" rel=\"noopener\">ovdje<\/a>.<\/span><\/p>","protected":false},"excerpt":{"rendered":"<p>Emotet sada koristi Microsoft OneNote priloge kako bi zaobi\u0161ao sigurnosne mjere za\u0161tite i inficirao vi\u0161e korisnika. Stara taktika Emotet je ozlogla\u0161eni zlonamjerni softver koji se u pro\u0161losti \u0161irio preko Microsoft Word i Excel priloga&#46;&#46;&#46;<\/p>","protected":false},"author":1,"featured_media":4508,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[299,303,302,300,301,296],"class_list":["post-4506","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hronike","tag-emotet","tag-macro-skripte","tag-microsoft-excel","tag-microsoft-onenote","tag-microsoft-word","tag-spam"],"_links":{"self":[{"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts\/4506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/comments?post=4506"}],"version-history":[{"count":0,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts\/4506\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/media\/4508"}],"wp:attachment":[{"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/media?parent=4506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/categories?post=4506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/tags?post=4506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}