Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

FIFA World Cup Soccer theme - used in targeted PDF attacks

AVERT Labs shares this key threat to avoid:

Waka Waka FIFA 2010: Targeted PDF attack uses World Cup theme as bait
http://www.avertlabs.com/research/blog/index.php/2010/06/22/waka-waka-fifa-2010-targeted-pdf-attack-uses-world-cup-theme-as-bait/

QUOTE: We have seen instances from recent times where WorldCup themes have been extensively used as bait to lure unsuspecting users into opening malicious attachments. With lots of recently discovered vulnerabilities and wide spread distribution, pdf files appear to be a perfect vector for these kind of attacks. These threats could be delivered as emails or poisoned search engine results leading to malicious pdf’s.

This particular pdf file is directed at certain high profile targets. Upon executing the malicious pdf file on a vulnerable version of Adobe reader/ Acrobat, it drops an innocent pdf file as shown in the figure below to spoof the unsuspecting user.  This malicious pdf file drops and executes a malicious payload detected as BackDoor-ERZ, while the malicious pdf is detected as Exploit-pdf.b with 6022 DATS.