Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: PDF Launch Feature Abused to Carry ZeuS/ZBOT


20 Apr 2010   #1

Windows 7 & Windows Vista Ultimate
 
 
PDF Launch Feature Abused to Carry ZeuS/ZBOT

Adobe products certainly have become a target. Personally, I replaced Adobe Reader with an alternate PDF Reader. There are a number of open source readers available from PDFreaders.org - Get a Free Software PDF reader!.

Quote:
The ZeuS/ZBOT malware continues to uphold its notorious reputation. As we have seen in the past, ZBOT variants steal account credentials when users visit various social networking, online shopping, and bank-related websites.

Another social engineering tactic that has been employed by ZeuS/ZBOT perpetrators is the use of .PDF files. Specially crafted .PDF files have been used as a vehicle for malware propagation by exploiting different vulnerabilities discovered in Adobe Reader and Acrobat.

Recently, however, we spotted a specially crafted .PDF file that drops a ZBOT variant without exploiting a vulnerability. Instead, this malicious file exploits a legitimate Adobe Reader feature. The said feature is the /launch function in the PDF specification, as security researcher Dieder Stevens demonstrated in his blog. This function allows a portable document author to attach an executable file and, via social engineering, trick users to save and run the embedded file.
Full story: PDF Launch Feature Abused to Carry ZeuS/ZBOT | Malware Blog | Trend Micro

My System SpecsSystem Spec
.

Reply

 PDF Launch Feature Abused to Carry ZeuS/ZBOT




Thread Tools




Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 04:21 AM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33