Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How about PDF support? #66

Open
yoshimo opened this issue May 3, 2023 · 0 comments
Open

How about PDF support? #66

yoshimo opened this issue May 3, 2023 · 0 comments

Comments

@yoshimo
Copy link

yoshimo commented May 3, 2023

PDF is the newest attack vector in Qakbot campaigns.
The format itself is portable and used widely.

There can be JS inside, exploits of the reader itself or social engineering that tricks the user into downloading the second stage loader of the infection from an external website masquerading as secure cloudstorage.
Often protected by short passwords to further prevent automatic analysis.

There are tools like danger zone to cut out active content from incoming mails and pdf examiner and quicksand to find malicious attachments but so far there is no way to automatically have them treat mail attachments and the social engineering part seems to be missing a detection method.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant