On The Insider: Joe Simpson to Produce TV Show
BNET Business Network:
BNET
TechRepublic
ZDNet

October 23rd, 2007

Attack of the PDFs

Posted by Ryan Naraine @ 1:13 pm

Categories: Botnets, Browsers, Data theft, Digital rights management, Exploit code, McAfee, Microsoft, Patch Watch, Responsible disclosure, Spam and Phishing, Symantec, Viruses and Worms, Vulnerability research

Tags: Software, Adobe Systems Inc., Symantec Corp., Adobe PDF, Attack, DeepSight Team, Security, E-mail, Viruses And Worms, Online Communications

Attack of the PDFsLess than 24 hours after Adobe shipped a fix for a gaping hole affecting its Reader and Acrobat software, PDF files rigged with malware are beginning to land in e-mail spam filters.

The discovery of the active attacks have underlined the need for Windows users to immediately scan machines for vulnerable software (I recommend the Secunia’s free software inspector) and immediately apply all necessary patches.

According to Erik Kamerling, an analyst in Symantec’s DeepSight Threat Management System team, the e-mail-borne attack is using the ‘mailto: option’ vulnerability discussed by Petko D. Petkov in September and confirmed earlier this month by Adobe.

[ SEE: Free utility looks for missing security patches ]

Symantec has tagged the threat as Trojan.Pidief.A, a malware file that’s being used to lower security settings and download more malicious executables on to the compromised computer.
The rigged document is delivered as a piece of spam with a filename such as ‘BILL.pdf’ or ‘INVOICE.pdf’.

When executed, Kamerling said the malicious code tries to disable the Windows Firewall with a ‘netsh firewall set opmode mode=disable’ command, and then downloads a remote file via FTP from 81.95.146.130 (the remote file is ‘ldr.exe’ and is a Downloader trojan).

At 4:00 PM EST, the host 81.95.146.130 is alive and still currently serving ‘ldr.exe’ over FTP. This server is known for hosting malicious software, Kamerling warned.

The DeepSight team is recommending that network administrators:

  • Block the delivery of PDF files in email.
  • Advise employees to not read or execute PDF files from unknown or untrusted sources.
  • Block access to the network and IP address involved in this attack.
  • Apply the patches outlined in Adobe Advisory APSB07-18 as soon as possible.

Ken Dunham, director of global response at iSIGHT Partners, said the attackers are using two rootkit files to sniff and steal financial and other valuable data from hijacked computers. The rootkits are installed in the Windows directory as 9129837.exe and new_drv.sys.

[SEE: ‘High risk’ zero-day flaw haunts Adobe Acrobat, Reader ]

“Anti-virus detection is extremely poor for the exploit files and payloads involved in this attack, averaging only 26 percent out of 39 updated programs tested during the time of attack,” Dunham said, nothing that the two attack servers are linked to the notorious Russian Business Network (RBN).

Dunham has found linkages between this attack and the zero-day Vector Markup Language (VML) attacks from September 2006. “Servers in the attack are also linked back to other malicious attacks involving Animated Cursor exploitation and Snifula and CoolWebSearch installations of code,” he said.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 57 Talkback(s)
Wow
It's amazing how hackers can find ways to exploit our computers these days, if there is a way seems they'll find a way no matter how we try to stop them...

- John Musbach... (Read the rest)
Posted by: John Musbach Posted on: 11/14/07 You are currently: a Guest | | Terms of Use
Adobe's misleadingly broken 7.0.x updater  dpnewkirk | 10/23/07
Reason 4,534 not to use Windows (NT)  DarthRidiculous | 10/23/07
re:Reason 9,129,837.exe NOT to use Winblows (nt)  n0neXn0ne | 10/23/07
Use Foxit Reader  osreinstall | 10/23/07
yep  The_Curmudgeon | 10/24/07
Yes there is.  osreinstall | 10/24/07
UNINSTALL Adobe Acrobat and get Foxit Reader  zookeeperz@... | 10/26/07
Not completely  osreinstall | 10/26/07
Great, nice alternative!  thx-1138_@... | 10/27/07
You're Welcome  osreinstall | 10/27/07
Reason 4,534 to run as a standard user account  PB_z | 10/24/07
Amen!  ttocsmij | 10/24/07
Sort of like what Linux does .  Intellihence | 10/24/07
another reason to use the UAC .  qmlscycrajg | 10/24/07
What about shared folders?  JCitizen | 10/24/07
again Linux is safe  Linux Geek | 10/24/07
Nothing is safe!  GovTech | 10/24/07
Except for Mac OS  Geotopia | 10/24/07
There are crackers out there  alaniane@... | 10/24/07
Well ,,,  Intellihence | 10/24/07
It's not "absolut security"...  Resuna | 10/24/07
thanks  ttocsmij | 10/24/07
I appologize if I ever called you a hacker..  JCitizen | 10/24/07
Since when  thammr | 10/24/07
Ya know...  Wolfie2K3 | 10/24/07
Re: Ya Know  kordoniss@... | 10/25/07
RE: Attack of the PDFs  chris.copp@... | 10/24/07
Source of IP Address  Geotopia | 10/24/07
PDF attack  cassam | 10/24/07
Excuse me...  SpikeyMike | 10/24/07
Ignorance sure is bliss my friend .  Intellihence | 10/24/07
Umm...pretty sure they already know  wolfsouls | 10/24/07
Internet "slut" is safe  SteveMak | 10/24/07
No Safety in Numbers  jmika@... | 10/24/07
wrong assumption  SpikeyMike | 10/24/07
Internet Junkie  chromeronin | 10/24/07
Ach!  ttocsmij | 10/24/07
Or better yet,  itpro_z | 10/24/07
My friend the majority of Windows users are not like you .  Intellihence | 10/24/07
Wisdom indeed  arowe@... | 10/25/07
"Block the delivery of PDF files in email"??  denisdubois | 10/24/07
knee jerk  ttocsmij | 10/24/07
Burnt Offerings  tsmit13@... | 10/24/07
RE: Attack of the PDFs  kathi@... | 10/24/07
RE: Attack of the PDFs  flotsam70 | 10/24/07
RE: Attack of the PDFs  addar@... | 10/24/07
another reason to use the UAC  qmlscycrajg | 10/24/07
RE: Attack of the PDFs  crawdad2k | 10/24/07
RE: Attack of the PDFs  dave@... | 10/24/07
You'd think they could...  Wolfie2K3 | 10/24/07
Very good points!  thx-1138_@... | 10/25/07
FOXIT READER  page.jason@... | 10/24/07
What enemies?  jeanjaz | 10/24/07
Exactly  kyussmondo | 10/25/07
Blacklist  dave@... | 10/29/07
Sorry  dave@... | 10/29/07
Wow  John Musbach | 11/14/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here