M$ Word and Excel Virus spotted in Europe !

Talk about anything at all....
Post Reply
User avatar
henke54
Posts: 382
Joined: Thu Apr 02, 2009 6:10 pm
Location: Flanders Belgium

M$ Word and Excel Virus spotted in Europe !

Post by henke54 »

The virus that was spread by the Citadel botnet is called Dorifel and infects Microsoft Word and Microsoft Excel documents as well as executable files, according to the NCSC. Microsoft calls the virus Quervar.B and notes that it has been observed contacting remote hosts in order to download files onto computers.

The virus spread via systems that were infected with Citadel for some time, infecting thousands of documents, the NCSC said. Dorifel is known as a banking Trojan designed to steal banking data and log-in credentials, it added. The virus damages Office files, rendering them unreadable via encryption, but the files are not destroyed.

If a user opens the file the virus can spread further via connected network discs, the NCSC said. The infection is activated after a system reboot and then starts looking for Office files.
:roll:
LibreOffice 6.0.7.3
on Linux Mint Mate
User avatar
henke54
Posts: 382
Joined: Thu Apr 02, 2009 6:10 pm
Location: Flanders Belgium

Re: M$ Word and Excel Virus spotted in Europe !

Post by henke54 »

Dorifel had encrypted most Excel and Word documents and converted them into executable files.

The result was that many government staff had to blow the dust of the old fashioned typewriters again as they were asked to leave their computers switched off in an attempt to stop the outbreak in its tracks.
:roll:

'SIDE NOTES' :
Yesterday it was a dark day for many companies in Europe, but especially in the Netherlands. A piece of malware known as Worm.Win32.Dorifel infected over 3000 machines globally, and 90% of infected users were both from public and business sector organizations based in the Netherlands.
:P
LibreOffice 6.0.7.3
on Linux Mint Mate
User avatar
acknak
Moderator
Posts: 22756
Joined: Mon Oct 08, 2007 1:25 am
Location: USA:NJ:E3

Re: M$ Word and Excel Virus spotted in Europe !

Post by acknak »

Does anyone know whether these are infecting the old MS Office binary files, or can they hit the newer xml formats as well?
AOO4/LO5 • Linux • Fedora 23
User avatar
henke54
Posts: 382
Joined: Thu Apr 02, 2009 6:10 pm
Location: Flanders Belgium

Re: M$ Word and Excel Virus spotted in Europe !

Post by henke54 »

acknak wrote:Does anyone know whether these are infecting the old MS Office binary files, or can they hit the newer xml formats as well?
According to mcafee :
mcafee wrote:XDocCrypt.a belongs to a family of malware which encrypts Microsoft Office word, Excel and Executable files
present in the system. It encrypts these files using RC4 encryption Algorithm. On successful encryption, the
original file will be replaced with the infector followed by encrypted data; and if the original file name has
“.doc”/”.docx” then it will be replaced by “U+202Ecod.scr”, if original filename has “.xls/.xlsx” then it will be
replaced by “U+202Eslx.scr”,
https://kc.mcafee.com/corporate/index?p ... id=PD23930
LibreOffice 6.0.7.3
on Linux Mint Mate
User avatar
Hagar Delest
Moderator
Posts: 32655
Joined: Sun Oct 07, 2007 9:07 pm
Location: France

Re: M$ Word and Excel Virus spotted in Europe !

Post by Hagar Delest »

Well, it could have happened to ODF too I guess, or any other file format. It's hardly a file format issue.
LibreOffice 7.6.2.1 on Xubuntu 23.10 and 7.6.4.1 portable on Windows 10
Post Reply