Author Topic: PDF malware adopts another obfuscation trick in attempt to avoid detection  (Read 673 times)

0 Members and 1 Guest are viewing this topic.

April 06, 2012, 07:59:14 pm
Read 673 times

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3312
http://nakedsecurity.sophos.com/2012/04/05/ccittfax-pdf-malware/

Quote
Filters are used by PDFs to compress or store data to either make the file smaller (Flate, CCITTFax) or allow it to be read as text (ASCIIHex).

By combining the filters in weird ways the malware author hopes to bypass detection by malware scanners and deliver a malicious payload to the victim.

example
http://wepawet.cs.ucsb.edu/view.php?hash=e44cc8b05cbca3500848285095704f8b&type=js
Ruining the bad guy's day