Friday, October 26, 2007

Adobe , spammers and a vulnerability

No we aren't Dead yet , just a little busy in the last month.
Probably you've heard about recent PDF spam attack (see also : TheRegister.co.uk & SANS.org ), despite Adobe company released Patch to fix this serious 0day vulnerability in its "Acrobat" and also "Reader" but hackers (read it spammers) are tries flooding inboxes with theirs malicious PDFs
some days ago I received a mail contains a pdf which exploit this vulnerability. attachment name is "invoice.pdf" and when I ran this file it attempted to download another malware .i looked the pdf with a hex editor and .....


as you can see malware tries to disable firewall and download a file from remote ftp.

See you to the next post ;)

Digg this

No comments: