techPowerUp! Forums

Go Back   techPowerUp! Forums > Hardware > Networking & Security

Reply
 
Thread Tools
Old Mar 25, 2011, 07:40 PM   #1
scaminatrix
2000 Posts
 
scaminatrix's Avatar
 
Join Date: Mar 2010
Location: By the Channel Tunnel, Kent, England
Posts: 2,432 (2.06/day)
Thanks: 1,834
Thanked 802 Times in 672 Posts

System Specs

Security risk: Spam e-mail from "puremobile.com" confirming order! Virus through pdf?

Hi all. I just got these 2 e-mails in my gmail account:

1st e-mail


2nd e-mail


If anyone gets this e-mail, don't open the pdf file for security reasons.

How likely is it that the PDF file is a virus?
__________________
MKMods Tribute Rig - the Power of the Community
HeatWare
Did I make the 2,000,000th post?
If an 8 Core can hit 6Ghz with an H100 i'll post pictures of my hot fiance - Pestilence
Every day I come to this site, I am reminded why I come to this site every day!!! - Iggster
scaminatrix is offline  
Reply With Quote
Old Mar 25, 2011, 07:53 PM   #2
erocker
Senior Moderator
 
erocker's Avatar
 
Join Date: Jul 2006
Location: Milwaukee, WI.
Posts: 31,958 (12.77/day)
Thanks: 2,793
Thanked 12,321 Times in 7,832 Posts

System Specs

Unless I purchased something from a site called "puremobile" I would have no reason to open the email and most definitely not open some attatched file. That's virus protection 101.
erocker is offline  
Reply With Quote
Old Mar 25, 2011, 07:59 PM   #3
stefan95p
 
Join Date: Mar 2011
Posts: 1 (0.00/day)
Thanks: 0
Thanked 0 Times in 0 Posts

*

Last edited by stefan95p; Feb 20, 2012 at 12:38 PM.
stefan95p is offline  
Reply With Quote
Old Mar 25, 2011, 08:04 PM   #4
Black Panther
Senior Moderator™
 
Black Panther's Avatar
 
Join Date: May 2007
Posts: 7,063 (3.23/day)
Thanks: 2,170
Thanked 1,842 Times in 1,105 Posts

System Specs

I got something similar on the work email address. I don't remember the name of the company because it was some months ago. They said I had purchased some shoes costing some €700 and that the amount was debited from my visa. And yup I needed to open some file.

I was nearly 100% sure it was a spam. But to check I went into my internet banking, found that no such debit had been effected from my account, and then deleted the email.

Absolutely do not open files from such emails. If the info troubles you check your internet banking or if not available go to your bank. It's very likely only a scam.
Black Panther is offline  
Reply With Quote
Old Mar 25, 2011, 08:10 PM   #5
brandonwh64
Addicted to Bacon and StarCrunches!!!
 
brandonwh64's Avatar
 
Join Date: Sep 2009
Location: Chatsworth, GA
Posts: 13,571 (10.00/day)
Thanks: 2,149
Thanked 5,342 Times in 3,697 Posts
Send a message via ICQ to brandonwh64 Send a message via AIM to brandonwh64 Send a message via MSN to brandonwh64 Send a message via Yahoo to brandonwh64

System Specs

No puremobile exists or it usta exist cause i bought a Motorola V3I with Itunes *Unlocked* back in 2007 so i could use on my deployment to iraq
__________________
Cruncher's:
All GPU's
GPU's:
7970 3GB *Unlocked* = 8 Threads
5770 1GB OCed = 2 Threads
brandonwh64 is offline  
Crunching for Team TPU
Reply With Quote
Old Mar 25, 2011, 08:11 PM   #6
scaminatrix
2000 Posts
 
scaminatrix's Avatar
 
Join Date: Mar 2010
Location: By the Channel Tunnel, Kent, England
Posts: 2,432 (2.06/day)
Thanks: 1,834
Thanked 802 Times in 672 Posts

System Specs

Quote:
Originally Posted by erocker View Post
Unless I purchased something from a site called "puremobile" I would have no reason to open the email and most definitely not open some attatched file. That's virus protection 101.
I always check the contents of the e-mail just to see how bad (laughable) it is. Gmail blocks images etc. by default for me, so I don't have to worry too much about opening the e-mail. Ofc, the attachment stays unopened.
Aah, the good old days when I would just get my laptop out and infect myself for the lulz!

Quote:
Originally Posted by stefan95p View Post
Hi scaminatrix,
I got this e-mail, too and I searched in Google for that firm. The firm does exist, but the mail seems to be spam
Here's a thread in the Gmail Forum about that: http://www.google.com/support/forum/...049f53ef9d06c6
And I was so stupid to open the file... Hope I didn't get a virus on my computer... Norton Internet Security 2011 didn't say anything!?
Regards!
Aah man, since you opened the PDF, I suggest you download Malware Bytes Anti-Malware and run a full scan mate.
Personally, I would also ditch Norton and use Avast! free version, but that's down to preference.

Quote:
Originally Posted by Black Panther View Post
I got something similar on the work email address. I don't remember the name of the company because it was some months ago. They said I had purchased some shoes costing some €700 and that the amount was debited from my visa. And yup I needed to open some file.
I was nearly 100% sure it was a spam. But to check I went into my internet banking, found that no such debit had been effected from my account, and then deleted the email.
Absolutely do not open files from such emails. If the info troubles you check your internet banking or if not available go to your bank. It's very likely only a scam.
Yea, first thing I did was check my Paypal, since that's the only thing that's registered to the Gmail account (no online banking, etc).

The thing I'm wondering the most - is it possible to send a virus through a .pdf file?

Quote:
Originally Posted by brandonwh64 View Post
No puremobile exists or it usta exist cause i bought a Motorola V3I with Itunes *Unlocked* back in 2007 so i could use on my deployment to iraq
Yea, it's still about now.
Here's something interesting:

Quote:
Received the same 2 emails and opened both pdf's
Pdfs were damaged and contained a list of PayPals

Still waiting for the backlash
http://www.dslreports.com/forum/r256...is-Puremobile-

Seems it's an Adobe exploit.
Quote:
Win32/Pdfjsc is the detection for a family of specially crafted PDF files that exploit Adobe Acrobat and Adobe Reader vulnerabilities. These files contain a JavaScript that executes when the file is opened.

The embedded JavaScript may contain malicious instructions, such as commands to download and install other malware. Files detected as Exploit:Win32/Pdfjsc may arrive in the system when a user visits a compromised or malicious webpage, or opens a malicious PDF email attachment.
http://www.microsoft.com/security/po...e=Win32/Pdfjsc
__________________
MKMods Tribute Rig - the Power of the Community
HeatWare
Did I make the 2,000,000th post?
If an 8 Core can hit 6Ghz with an H100 i'll post pictures of my hot fiance - Pestilence
Every day I come to this site, I am reminded why I come to this site every day!!! - Iggster

Last edited by scaminatrix; Mar 25, 2011 at 08:20 PM.
scaminatrix is offline  
Reply With Quote
The Following 3 Users Say Thank You to scaminatrix For This Useful Post:
Old Apr 15, 2011, 04:51 PM   #7
od8086
 
Join Date: Apr 2011
Location: hungary
Posts: 1 (0.00/day)
Thanks: 0
Thanked 2 Times in 1 Post

Hi. I'm working in the field of malware analysis, and at the company it was my duty to process these PDF samples. The files are malformed, and there is a malicious exploit too. If anybody is interested, just open the PDF (in a safe environment, VMWare for example), in Acrobat Reader, and when it grows to around 250 MB in the memory, save the whole dump. Search for the string JAAAA, and there will be many hits. That is one part of the injected shellcode (I dont remember the others, at home I didn't have the infected samples ), and the technique used is called heap spraying (wikipedia, or just google it), that's why it grows in the memory. The essence of this exploitation method is to fill a big array in the memory with shellcode, then use some bug, to crash specific parts of the running program. In this case, there's a possibility of passing the control flow to the machine-code filled array, and voila.. In this case, I think it works only under certain versions of Acrobat Reader (and the version of the OS is crucial, too). Maybe before v9.2, I think, but haven't tested yet. Because of many reasons, especially in the case of suscpicious PDF files, don't trust just one AV software - use virustotal.com for example, or open it using google viewer.
od8086 is offline  
Reply With Quote
The Following 2 Users Say Thank You to od8086 For This Useful Post:
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Is Security Software Becoming a Security Risk? Polaris573 News 4 Nov 26, 2007 06:17 PM


All times are GMT. The time now is 05:40 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts