HomeSecurityWindows zero-day: JavaScript files bypass MoTW

Windows zero-day: JavaScript files bypass MoTW

A new Windows zero-day allows threat actors to use malicious standalone JavaScript files to bypass Mark-of-the-Web security warnings .

See also: A zero-day in Windows Mark of the Web gets an unofficial update

zero day

Windows includes a security feature called Mark-of-the-Web (MoTW), which marks a file as having been downloaded from the Internet and therefore should be treated with caution as it could be malicious .

MoTW is added to a file or email you have received, as a special alternative data stream called “Zone.Identifier“, which can be viewed using the “dir /R” command and opened directly in Notepad.

This alternative “Zone.Identifier” data stream includes the URL security zone the file came from , the referring link, and the URL to the file.

When a user attempts to open a file that has been marked by Mark-of-the-Web, Windows will display a warning that the file should be treated with caution.

Microsoft Office also uses MoTW to determine whether the file should be opened in Protected View, which results in macros being disabled.

HP's threat intelligence team recently reported a zero-day that allows threat actors to infect devices with Magniber ransomware using JavaScript files.

See also: 900 servers compromised using a zero-day Zimbra vulnerability

These are not JavaScript files commonly used on almost all websites, but .JS distributed by threat actors as attachments or downloads that can be executed outside of a web browser.

JavaScript files distributed by Magniber threat actors are digitally signed using an embedded base64, according to Microsoft.

JavaScript

After the zero-day was analyzed by Will Dormann, a senior vulnerability analyst at ANALYGENCE, he discovered that the attackers signed these files with a malformed key.

When signed in this way, even though the JS file was downloaded from the Internet and was flagged by MoTW, Microsoft does not display a security warning and the script is automatically executed to install the Magniber ransomware.

Using this technique, threat actors can bypass the normal security warnings that appear when opening downloaded JS files and automatically execute the script.

Dormann said threat actors could modify any Authenticode-signed file, including executable (.EXE) files, to bypass MoTW security warnings.

See also: Microsoft Exchange: Zero-day mitigation can be bypassed

To do this, Dormann says that a signed executable file can be modified using a hex editor, to change some of the bytes in the signature section of the file and thus destroy the signature.

Once the signature is corrupted, Windows will not check the file using SmartScreen, as if there was no MoTW flag, and will allow it to run.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS