Showing posts with label PDF. Show all posts
Showing posts with label PDF. Show all posts

Monday, 27 April 2015

Malicious Word Document Hidden In A PDF File


Frequently happens that attackers use DOC and PDF files to infect internet users with malware, but recently a researcher found a PDF file called "Sales Invoice" that contained a malicious Word document.When opening the PDF file is via Javascript tried to open an embedded Word document. Standard warns Adobe Reader to open these embedded files.

If users ignore the warning and still choose to open the DOC file in Microsoft Word, then get them whether they want to run the macro in the document. In recent months, regular Word documents with macros used , which once carried download malware. Also in this case, it is after the execution of the macro malware downloaded. It is a variant of the Dridex banking Trojan, a Trojan horse that steals money from online bank accounts.

According to researcher Steve Basford the malicious Office documents at the time only against Windows users. "Apple and Android software to open these attachments and might even run the macros embedded in the annex," he tells his own blog.Belgian researcher and ISC handler Didier Stevens made ​​this demonstration video in which he analyzes the PDF file.

Friday, 12 December 2014

Microsoft - Beware of Payment Report Malware


Microsoft has warned Windows users to a malicious spam attack that attempts to infect recipients with malware. In the mail, with the subject "Payment Report - importan", it is stated that the recipient of the email received an amount of $ 35,000.

More details would be in the included zip find attached. The zip appendix contains a .scr file with a PDF icon. Because Windows default file extension does not display, users would have thought that it is a PDF document. Depending on the set display of folders, Windows will still show that it is a screensaver.


If the attachment is opened the computer becomes the Upatre downloader infected. This downloader can then again download other malicious software. According to Microsoft, the malware would be seen especially in consumer and business computers in North America.


MD5: 5a0e6a8f6d3afd811a109df2e1ee727b


 Virustotal Report