InvisiBill
2[H]4U
- Joined
- Jan 2, 2003
- Messages
- 2,608
FYI, I just got an email with an infected attachment. https://www.virustotal.com/file-sca...b28d7af750d4dc00df8b496cfcf8820212-1301053048 Currently only MS and AntiVir are actually detecting it.
http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Pdfjsc
http://www.adobe.com/support/security/advisories/apsa11-01.html is Adobe's page about the vulnerability.
Adobe recommends users update to Adobe Flash Player 10.2.153.1 (Adobe Flash Player 10.2.154.25 for Chrome users).
Adobe recommends users update to Adobe Acrobat 9.4.3 or Adobe Acrobat X 10.0.2.
The email that I got looked like this, and had "OrderN25031135.pdf" attached.
I haven't had much time to dissect the PDF yet, but you should avoid opening these files if you use Adobe PDF products.
http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Pdfjsc
Win32/Pdfjsc is the detection for a family of specially crafted PDF files that exploit Adobe Acrobat and Adobe Reader vulnerabilities. These files contain a JavaScript that executes when the file is opened.
The embedded JavaScript may contain malicious instructions, such as commands to download and install other malware. Files detected as Exploit:Win32/Pdfjsc may arrive in the system when a user visits a compromised or malicious webpage, or opens a malicious PDF email attachment.
http://www.adobe.com/support/security/advisories/apsa11-01.html is Adobe's page about the vulnerability.
Adobe recommends users update to Adobe Flash Player 10.2.153.1 (Adobe Flash Player 10.2.154.25 for Chrome users).
Adobe recommends users update to Adobe Acrobat 9.4.3 or Adobe Acrobat X 10.0.2.
The email that I got looked like this, and had "OrderN25031135.pdf" attached.
Subject: Your Order No 461316 | Puremobile Inc.
Date: Fri, 25 Mar 2011 05:04:45 -0400
From: PuremobileInc. <[email protected]>
Thank you for ordering from Puremobile Inc.
This message is to inform you that your order has been received
and is currently being processed.
Your order reference is 18105.
You will need this in all correspondence.
This receipt is NOT proof of purchase.
We will send a printed invoice by mail to your billing address.
You have chosen to pay by credit card.
Your card will be charged for the amount of 645.00 USD
and "Puremobile Inc." will appear next to the charge on your statement.
Your purchase information appears below in the file.
Puremobile Inc.
I haven't had much time to dissect the PDF yet, but you should avoid opening these files if you use Adobe PDF products.
Last edited: