Home > Information Security News > PDF attack code complicates security analysis, skirts detection
Information Security News:
EMAIL THIS

PDF attack code complicates security analysis, skirts detection

By Robert Westervelt, News Editor
11 Jan 2010 | SearchSecurity.com

Security UK News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

One of the latest PDF attacks is using more sophisticated shellcode, making analysis of malware more difficult for security researchers while slowing antivirus detection.

The attack, detected over the last few days, looks like a run-of-the-mill malicious PDF file, but its coding contains a second layer that doesn't use the Web to download code, making antivirus detection more difficult.

In an interview with SearchSecurity.com, Bojan Zdrnja, senior information security consultant at Croatia-based security firm Infigo IS, said the malicious code was not working because it was only 38-bytes, but a closer look revealed a second layer written by a savvy malware writer.

"Normally, malicious PDFs like this execute shellcode and then download further things off the Web," Zdrnja said. "This one had everything embedded so it was as stealthy as possible; no connections are made to the Web at all."

Zdrnja said the sophisticated coding is alarming and something that researchers will be tracking in 2010.

"I'm also worried with the fact that the attacker tried to make this as stealthy as possible since the malicious PDF document drops another, benign PDF document so the victim does not become suspicious," he said. "I think that we will almost certainly see more of such sophisticated attacks in 2010."

The malware author used an egg-hunting shellcode, which hunts for a block of code in the file to execute, rather than downloading malicious data at the time of a successful attack. The hidden code it uses is contained in a color object within the PDF document. Egg-hunting shellcode is normally used in exploits when there is limited buffer space, Zdrnja said. PDF documents typically give as much space as a malware coder needs. Zdrnja said the use of the technique shows that the author is working harder to avoid detection and stifle malware analysis.

Zdrnja wrote extensively about his malicious PDF analysis in a SANS Internet Storm Center diary entry. The specific malicious PDF file attempts to target a JavaScript zero-day vulnerability in Adobe Acrobat and Reader. Zdrnja said it drops two binaries - a harmless PDF file, designed to open Adobe Reader and make the user believe the file attachment is harmless and a second file, designed to enable the malware.

In an advisory, Adobe Systems Inc. said it would issue a patch for the vulnerability during its regular updates scheduled for Jan. 12. The vulnerability being targeted is contained in Acrobat Reader and Acrobat 9.2. In an advisory issued Dec. 15, Adobe said the remote code execution vulnerability is being actively targeted by attackers in the wild via malicious email PDF attachments.

To mitigate the threat, Adobe users can disable JavaScript until a patch is released and avoid opening PDFs from untrusted sources. Danish vulnerability clearinghouse Secunia has given the vulnerability an extremely critical rating.

Tags: Email and Instant Messaging SecurityWeb Application SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Email and Instant Messaging Security
Websense integrated security system aims to simplify security management
Preventing phishing attacks: Enterprise best practices
Chinese hacker attacks target Google Gmail accounts, top tech firms
Understand role-based access control in Microsoft Exchange 2010
Yahoo login credentials at risk to hijacking attack
Top spammer gets four years in jail for stock fraud scheme
M86 buys Web security gateway vendor Finjan
Web-based attacks skyrocket, pirating sites surge, security firms say
Pushdo botnet uses Facebook to spread malicious email attachment
Phishing protection begins with training, antiphishing evangelist

Web Application Security
Social networking risks, benefits for enterprises weighed by RSA panel
How to prevent Adobe hacks from affecting your organisation
Securing Web applications with Web application firewalls
CISOs take measured steps to reduce social media risks
Google to pay for Chrome browser vulnerabilities
Facebook, McAfee partner to fix social network security issues
Annual security reports offer some hope
Firefox, Opera, Safari browsers top list of high risk software
Active PDF attacks target Reader, Acrobat zero-day vulnerability
Using unique device identification for bank website security

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Serious Organized Crime Agency  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



IT Solutions for the UK: Data Security, Network Security, Application Security