Skip to main content

Microsoft Publisher files spread backdoor to steal corporate data, Bitdefender warns

  • September 13, 2016
  • 1 reply
  • 185 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
This is different, be alert for any e-mails containing .pub attachments
 
13th September 2016  By Alexandra Gheorghe
 
                                              


 
Recipients are advised to open the files with Microsoft Publisher, a paid desktop publishing software application embedded in Microsoft Office 365. It’s commonly used as an editor and layout tool for creating leaflets, postcards, newsletters, e-mail newsletters or greeting cards.
 
.Pub is not your typical file format to host malware,” says Adrian Miron, Head of Antispam Lab at Bitdefender. “Spammers have chosen it because people don’t usually associate this type of file with the possibility of infection.”
 
The .pub file contains a script (VBScript) that embeds a URL acting as a remote host. From this location, the malware downloads a self-extracting cabinet file containing an AutoIt script, a tool to run the script and an AES-256 encrypted file. The cyphered file can be decrypted using a key derived from the MD5 of a text written in the AutoIt file, antimalware researchers noticed.
 
Full Article
 
 

 

1 reply

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • September 13, 2016
I think that one should be suspicious of receiving any form of attachment if the source is unknown or the transmission is unexpected...and that should keep you safe in most circumstances.

Reply