Showing posts with label PDF Documents. Show all posts
Showing posts with label PDF Documents. Show all posts

Friday, 21 August 2015

Phishing Springboard Hidden In PDF Documents


PDF documents are often used to infect computers with malware, cyber criminals but the format now use to lure victims to phishing sites. Researchers at Kaspersky Lab discovered a PDF document that is distributed via an e-mail scam.

According to the email, the recipient of the message received $ 53,000 in his account. However, the recipient must confirm the transaction, which can be done via the enclosed PDF document. The PDF document contains only an illustration that states that the document is protected and offers the user a button to view the contents. The button, however, points to a phishing site which looks like a PDF document with transaction data.

To view the data, the user must then enter their email address and password. These data are sent to the criminals. According to analyst Dmitry Bestuzhev, this is an interesting technique that some phishing filters can mislead.

Sunday, 26 July 2015

US Government Attacked Via Flash Player Flaw


Several agencies of the US government in June and July attacked via a Flash Player vulnerability that was discovered by the Italian Hacking Team and true at the time of the attacks had no patch yet, says the FBI. Details about the vulnerability were found in the data that were stolen from the Italian surveillance company. However, the break-in at Hacking Team was made ​​public on July 6.

Now, according to information from the FBI's Flash Player flaw had been since June 8 by assailants known and actively used to penetrate US government agencies. Previously had anti-virus company Trend Micro already know that the vulnerability before the disclosure in targeted attacks against targets in Korea and Japan had begun, namely July 1 . The FBI goes in the case for the attacks against US government agencies for two campaigns which probably gathering information aim.

Campaigns

The first phishing campaign took place on 8, 9 and 11 June, the second was observed on July 8, according to a warning that spread the FBI and by Public Intelligence online ( pdf is put). Both attacks emails were sent with a link. The link pointed to an exploit that took advantage of the vulnerability in Flash Player. The attack on July 8, the FBI more information mentioned in the warning. Thus, the government received a spear phishing e-mail with a link to a PDF document. When users opened a website loaded there the link containing JavaScript code. This code then loaded a malicious Flash file that vulnerability in Flash Player attacked to infect your computer with malware.

The spear phishing emails had different topics such as 'BBW Analysis report - 2015', 'Tomorrow Morning New Starts', "Perry Dale Club for Leadership: Financial Literacy 101", "FAS Analysis Report - 2015", "AEP Energy Program Update: 2015 Program Year Kick Off ',' Review Link "and" PLS Account A42660861. All spear phishing emails that were submitted in July had the same sender. The timing of the attack in July is remarkable, because on July 8 wrote poetry namely the vulnerability in Adobe Flash Player version 18.0.0.194 and earlier on an emergency patch . In the warning, the FBI also recorded several IP addresses and domains that were used by the attackers and can help detect a possible attack.

Wednesday, 18 February 2015

New oclHashCat Can Crack Protected PDF Documents


There is a new version of the popular password cracker oclHashcat appeared which now supports the cracking of password-protected PDF documents. Furthermore oclHashcat supports version 1:33 now 150 different algorithms, there is added a PBKDF2 kernel, the multithreaded loading glossaries supported and there are several other minor changes and fixes.

OclHashcat is a program that uses the processing power of the graphics card to crack password hashes. There is also a version called Hashcat that the power of the processor committed. From 1:33 Hashcat version two versions have appeared. A version optimized for video cards with an AMD chipset and a version intended for owners of Nvidia graphics card. Both Hashcat as oclHashcat used by security professionals, security researchers and penetration testers.