V
Virus Guy
I've received two e-mails today with the following characteristics:
Sending ip: 70.91.136.218, 83.174.248.144
Subject: (blank - no subject text)
User-Agent: Thunderbird 1.5.0.12 (Windows/20070509)
No visible message body, only an attachment with one of these names:
message.zip (21,722 bytes)
request.zip (7.385 bytes)
They decompress to (respectively):
message.pdf (22,902 bytes, Friday Aug 3, 12:11:54 pm)
request.pdf (8,884 bytes, Friday Aug 3, 8:25:36 pm)
Both were submitted to VirusTotal (9:20 pm EST) and both showed 100%
clean
scan results.
Both files begin with this text:
%PDF-1.1
And contain this text within the first 200 bytes:
/Kids [3 0 R 4 0 R 5 0 R 6 0 R 7 0 R 8 0 R 9 0 R]
or
/Kids [3 0 R 4 0 R 5 0 R]
Either this is some new form of spam (where the message body is
contained in PDF file) or this is some new form of .PDF malware.
I can't see this as just a plain spam, delivered as a .PDF (because it
requires user intervention to render the body).
Sending ip: 70.91.136.218, 83.174.248.144
Subject: (blank - no subject text)
User-Agent: Thunderbird 1.5.0.12 (Windows/20070509)
No visible message body, only an attachment with one of these names:
message.zip (21,722 bytes)
request.zip (7.385 bytes)
They decompress to (respectively):
message.pdf (22,902 bytes, Friday Aug 3, 12:11:54 pm)
request.pdf (8,884 bytes, Friday Aug 3, 8:25:36 pm)
Both were submitted to VirusTotal (9:20 pm EST) and both showed 100%
clean
scan results.
Both files begin with this text:
%PDF-1.1
And contain this text within the first 200 bytes:
/Kids [3 0 R 4 0 R 5 0 R 6 0 R 7 0 R 8 0 R 9 0 R]
or
/Kids [3 0 R 4 0 R 5 0 R]
Either this is some new form of spam (where the message body is
contained in PDF file) or this is some new form of .PDF malware.
I can't see this as just a plain spam, delivered as a .PDF (because it
requires user intervention to render the body).