![]() |
|
|
#1 |
![]() Join Date: Mar 2010
Location: By the Channel Tunnel, Kent, England
Posts: 2,432 (2.06/day)
Thanks: 1,834
Thanked 802 Times in 672 Posts
|
Security risk: Spam e-mail from "puremobile.com" confirming order! Virus through pdf?
Hi all. I just got these 2 e-mails in my gmail account:
1st e-mail
2nd e-mail
If anyone gets this e-mail, don't open the pdf file for security reasons. How likely is it that the PDF file is a virus?
__________________
MKMods Tribute Rig - the Power of the Community HeatWare Did I make the 2,000,000th post? If an 8 Core can hit 6Ghz with an H100 i'll post pictures of my hot fiance - Pestilence Every day I come to this site, I am reminded why I come to this site every day!!! - Iggster |
|
|
|
|
|
#2 |
|
Senior Moderator
Join Date: Jul 2006
Location: Milwaukee, WI.
Posts: 31,958 (12.77/day)
Thanks: 2,793
Thanked 12,321 Times in 7,832 Posts
|
Unless I purchased something from a site called "puremobile" I would have no reason to open the email and most definitely not open some attatched file. That's virus protection 101.
|
|
|
|
|
|
#3 |
|
Join Date: Mar 2011
Posts: 1 (0.00/day)
Thanks: 0
Thanked 0 Times in 0 Posts
|
*
Last edited by stefan95p; Feb 20, 2012 at 12:38 PM. |
|
|
|
|
|
#4 |
|
Senior Moderator™
Join Date: May 2007
Posts: 7,063 (3.23/day)
Thanks: 2,170
Thanked 1,842 Times in 1,105 Posts
|
I got something similar on the work email address. I don't remember the name of the company because it was some months ago. They said I had purchased some shoes costing some €700 and that the amount was debited from my visa. And yup I needed to open some file.
I was nearly 100% sure it was a spam. But to check I went into my internet banking, found that no such debit had been effected from my account, and then deleted the email. Absolutely do not open files from such emails. If the info troubles you check your internet banking or if not available go to your bank. It's very likely only a scam. |
|
|
|
|
|
#5 |
|
Addicted to Bacon and StarCrunches!!!
Join Date: Sep 2009
Location: Chatsworth, GA
Posts: 13,571 (10.00/day)
Thanks: 2,149
Thanked 5,342 Times in 3,697 Posts
|
No puremobile exists or it usta exist cause i bought a Motorola V3I with Itunes *Unlocked* back in 2007 so i could use on my deployment to iraq
__________________
Cruncher's: All GPU's GPU's:
7970 3GB *Unlocked* = 8 Threads 5770 1GB OCed = 2 Threads |
|
|
|
|
|
#6 | ||||||
![]() Join Date: Mar 2010
Location: By the Channel Tunnel, Kent, England
Posts: 2,432 (2.06/day)
Thanks: 1,834
Thanked 802 Times in 672 Posts
|
Quote:
Aah, the good old days when I would just get my laptop out and infect myself for the lulz! Quote:
Personally, I would also ditch Norton and use Avast! free version, but that's down to preference. Quote:
The thing I'm wondering the most - is it possible to send a virus through a .pdf file? Quote:
Here's something interesting: Quote:
Seems it's an Adobe exploit. Quote:
__________________
MKMods Tribute Rig - the Power of the Community HeatWare Did I make the 2,000,000th post? If an 8 Core can hit 6Ghz with an H100 i'll post pictures of my hot fiance - Pestilence Every day I come to this site, I am reminded why I come to this site every day!!! - Iggster Last edited by scaminatrix; Mar 25, 2011 at 08:20 PM. |
||||||
|
|
|
|
|
#7 |
|
Join Date: Apr 2011
Location: hungary
Posts: 1 (0.00/day)
Thanks: 0
Thanked 2 Times in 1 Post
|
Hi. I'm working in the field of malware analysis, and at the company it was my duty to process these PDF samples. The files are malformed, and there is a malicious exploit too. If anybody is interested, just open the PDF (in a safe environment, VMWare for example), in Acrobat Reader, and when it grows to around 250 MB in the memory, save the whole dump. Search for the string JAAAA, and there will be many hits. That is one part of the injected shellcode (I dont remember the others, at home I didn't have the infected samples
), and the technique used is called heap spraying (wikipedia, or just google it), that's why it grows in the memory. The essence of this exploitation method is to fill a big array in the memory with shellcode, then use some bug, to crash specific parts of the running program. In this case, there's a possibility of passing the control flow to the machine-code filled array, and voila.. In this case, I think it works only under certain versions of Acrobat Reader (and the version of the OS is crucial, too). Maybe before v9.2, I think, but haven't tested yet. Because of many reasons, especially in the case of suscpicious PDF files, don't trust just one AV software - use virustotal.com for example, or open it using google viewer.
|
|
|
|
| The Following 2 Users Say Thank You to od8086 For This Useful Post: |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Is Security Software Becoming a Security Risk? | Polaris573 | News | 4 | Nov 26, 2007 06:17 PM |