Reply to topic  [ 6 posts ] 
PDF 0 - day Government Spy Assembler 0x29A Micro Backdoor 
Author Message
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 6:58 pm
Posts: 8767
Location: behind the sofa
Reply with quote
From here

Quote:
These malicious PDF files were rigged with exploits attacking Adobe Reader versions 9, 10 and 11, bypassing its sandbox


This is live now and actively being used for some incredibly cool spyware. There's a fairly detailed analysis of this complicated and carefully planned attack on the link.

    Mitigation and recommendations
    To protect against these attacks, we recommend that you:
  • Update Java to the latest version or simply remove it from
    the system if not used
  • Update Microsoft Windows and Office to the latest versions
  • Update Adobe Reader to the latest version
  • Block traffic to the following domains:
    arabooks.ch
    artas.org
    tsoftonline.com
    www.eamtm.com
    news.grouptumbler.com
  • Block traffic to the following IPs:
    200.63.46.23
    194.38.160.153
    95.128.72.24
    72.34.47.186
    188.40.99.143
    85.95.236.114
  • Install a security solution capable of detecting these threats such as Kaspersky Internet Security 2013 and scan all
    emails and received documents
  • Be wary of opening suspicious documents on your systems; instead, use another computer without an Internet
    connection, a VM, or upload the document to Google Docs for viewing
    In addition, infected PDFs contain the following string, which can be used as a quick way to find them:
    “@34fZ7E*p\”

_________________
jonbwfc's law: "In any forum thread someone will, no matter what the subject, mention Firefly."

When you're feeling too silly for x404, youRwired.net


Mon Mar 04, 2013 12:40 pm
Profile WWW
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
Very handy being a mac user. No Java installed at all. No Adobe reader as Preview can view PDF's.

Though I have little snitched installed and so will need to look at blocking those sites and links.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Mon Mar 04, 2013 1:50 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Very handy being a Windows 8 user, no Acrobat Reader installed here... ;)

Don't be too cocky, there have been several aimed attacks at Macs in the last couple of weeks.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Mon Mar 04, 2013 2:57 pm
Profile ICQ
I haven't seen my friends in so long
User avatar

Joined: Thu Jun 18, 2009 5:10 pm
Posts: 5837
Reply with quote
Very handy being a Linux User - no Acrobat installed here ... :lol:

...

_________________
Jim

Image


Mon Mar 04, 2013 3:04 pm
Profile
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 6:58 pm
Posts: 8767
Location: behind the sofa
Reply with quote
I don't know enough about other PDF readers to know if they are safe or not. I guess it largely depends whether they support Javascript.

I've heard some very bad things about Foxit and there have been real attacks on it. For example:

http://www.zdnet.com/blog/security/foxi ... -wild/2996

_________________
jonbwfc's law: "In any forum thread someone will, no matter what the subject, mention Firefly."

When you're feeling too silly for x404, youRwired.net


Mon Mar 04, 2013 4:03 pm
Profile WWW
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
big_D wrote:
Very handy being a Windows 8 user, no Acrobat Reader installed here... ;)

Don't be too cocky, there have been several aimed attacks at Macs in the last couple of weeks.

I am fully aware of that. It is always best to be fully prepared.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Mon Mar 04, 2013 5:38 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 6 posts ] 

Who is online

Users browsing this forum: No registered users and 11 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.