BITDEFENDER PARTNER MALAYSIA
  • Home
    • About Us
    • Why Bitdefender >
      • Patented Technology
  • FOR BUSINESS
    • Gravityzone Business Security >
      • Ransomware Mitigation
      • MITRE ATT&CK Evaluation
      • Gravityzone Technologies
      • Gravityzone Features List
    • Bitdefender Email Security >
      • Gravityzone Email Security Configuration (For Outlook 365)
      • Gravityzone Email Security Configuration (For Google Workspace)
    • Patch Management
    • Full Disk Encryption
  • SUPPORT
    • Payment mode
    • Request Quotation
    • Tips & Trends
    • Refund Policy
    • Privacy Policy
  • CONTACT US
    • Whatsapp us

22 years of Innovations

Microsoft Publisher files spread backdoor to steal corporate data, Bitdefender warns

9/27/2016

 
Picture
A targeted spam wave is infecting Windows computers with a backdoor capable of stealing sensitive corporate information from medium and small-sized businesses.
Bitdefender antispam researchers have identified a couple of thousand emails containing .pub attachments posing as orders and invoices for products. The email senders impersonate employees from small and medium-sized businesses from the UK and China, as well as other legitimate companies.
Picture
Picture
​Recipients are advised to open the files with Microsoft Publisher, a paid desktop publishing software application embedded in Microsoft Office 365. It’s commonly used as an editor and layout tool for creating leaflets, postcards, newsletters, e-mail newsletters or greeting cards.

.Pub is not your typical file format to host malware,” says Adrian Miron, Head of Antispam Lab at Bitdefender. “Spammers have chosen it because people don’t usually associate this type of file with the possibility of infection.”

The .pub file contains a script (VBScript) that embeds a URL acting as a remote host. From this location, the malware downloads a self-extracting cabinet file containing an AutoIt script, a tool to run the script and an AES-256 encrypted file. The cyphered file can be decrypted using a key derived from the MD5 of a text written in the AutoIt file, antimalware researchers noticed.
Picture
Fig. 1 Deobfuscated VBScript
Picture
Fig. 2 Decoded AutoIt script with MD5 for decryption key
Once the file is decrypted and installed, attackers have backdoor access and can control resources on the compromised computer. The malware can memorize keystrokes to record passwords and usernames, steal login information from browsers or emails, view system data and take other intrusive actions.
 “We have reason to believe that the stack originates from Saudi Arabia and the Czech Republic,” Miron adds.
Bitdefender detects and blocks the .pub file as W97M.Downloader.EGF and the backdoor paypload asGeneric.Malware.SFLl.545292C0.
 MD5: 8bcaf480f97eb43d3bed8fcc7bc129a4
To stay protected from this type of threats, Bitdefender advises companies to install a robust anti-spam filter. Users should avoid opening and downloading suspicious email attachments from unsolicited sources.
Technical analysis courtesy of Alexandru RUSU, Antimalware Researcher at Bitdefender and Adrian MIRON, Head of Antispam at Bitdefender.

 Source: Hot for Security powered by Bitdefender

Comments are closed.

    Protect from Ransomware

    Buy Bitdefender now

    Select carefully in the PayPal item below before make payment.
    Buy now and get protection. License key will be delivered before next business day. Activation in Malaysia only.

    Picture

    RECOMMENDED READINGs

    All
    ABC Of Cybersecurity
    Antivirus For Mac
    Biometric
    Child Online Safety
    CISO
    Corporate Security
    Cyberattacks
    Cybersecurity
    Data Center
    Data Center Security
    Data Leak
    Do Your Thing
    Endpoint Security
    Extortion
    Firewall Rules
    Goldeneye
    Gravityzone Business Security)
    Hacker
    Home Security
    Home User Products
    How To
    Hyperconvergence
    Installation Guide
    Intellectual Property
    Internet Of Things
    Internet Security
    IoT
    Loss Of Life
    Machine Learning
    Malware
    Online Purchase
    Online Security
    Parental Control
    Personal Security
    Petya
    Protected
    Ransomware
    Ransomware 2016
    Ransomware Decryption Tool
    Security Awareness
    Security Awareness Training
    Security Policies Setting
    Smb
    Virtualization & Cloud Security
    Wannacry
    Wanncry
    Windows Security

    RSS Feed

Picture
Chat with WhatsApp
Picture
Submit request or inquiry

For BUSINESS: Gravityzone Advanced Business Security

We are a certified Bitdefender Solution Partner (more than 9 years)

Copyright © 2025 We are a Gold Partner of Bitdefender.
About us | Contact us |
Copyright © 2024 57Network Consultancy Sdn. Bhd.
Company Registration number: 202001020346 (1376666-K) 
All rights reserved.

Website managed by 57Network.com
  • Home
    • About Us
    • Why Bitdefender >
      • Patented Technology
  • FOR BUSINESS
    • Gravityzone Business Security >
      • Ransomware Mitigation
      • MITRE ATT&CK Evaluation
      • Gravityzone Technologies
      • Gravityzone Features List
    • Bitdefender Email Security >
      • Gravityzone Email Security Configuration (For Outlook 365)
      • Gravityzone Email Security Configuration (For Google Workspace)
    • Patch Management
    • Full Disk Encryption
  • SUPPORT
    • Payment mode
    • Request Quotation
    • Tips & Trends
    • Refund Policy
    • Privacy Policy
  • CONTACT US
    • Whatsapp us