{"id":561,"date":"2018-09-12T15:23:30","date_gmt":"2018-09-12T13:23:30","guid":{"rendered":"http:\/\/btrnaidu.com\/?p=561"},"modified":"2018-09-12T15:48:53","modified_gmt":"2018-09-12T13:48:53","slug":"url-with-malware-in-pdf-attachment","status":"publish","type":"post","link":"https:\/\/btrnaidu.com\/index.php\/url-with-malware-in-pdf-attachment\/","title":{"rendered":"URL with Malware in pdf attachment"},"content":{"rendered":"<p>Today I received an email from &#8220;<span style=\"font-family: 'andale mono', monospace; font-size: 10pt;\">Barclays &lt;ruman@antimbd.com&gt;<\/span>&#8221; having subject &#8220;<span style=\"font-family: 'andale mono', monospace; font-size: 10pt;\">Account Alert &#8211; You have a new bill from Bank of America Credit Card<\/span>&#8220;.<\/p>\n<p><!--more--><\/p>\n<p>My eyebrows immediately went up as I dont have any credit card from Barclays.\u00a0 The email address &#8220;<span style=\"font-family: 'andale mono', monospace;\">ruman@antimbd.com<\/span>&#8221; looked suspicious.\u00a0 \u00a0The email has a pdf attachment and the message said,<\/p>\n<p><span style=\"font-family: 'andale mono', monospace; font-size: 10pt;\">For details of a recent payment made to you, please see the attached payment remittance advice.<\/span><\/p>\n<p><span style=\"font-family: 'andale mono', monospace; font-size: 10pt;\">Barclays_Payment_Remittance_Advice_95047145.pdf<\/span><\/p>\n<p><span style=\"font-family: 'andale mono', monospace; font-size: 10pt;\">If you have any queries or questions, our contact details are printed on the remittance advice.<\/span><\/p>\n<p>At once I thought, should I open the pdf or not.\u00a0 Trusting adobe, I open the pdf.\u00a0 The pdf has another link with some similar text which said, I should click here to view the bill.\u00a0 Now I was very certain that its a malware attack.\u00a0 I decided to verify if the url contains any virus.<\/p>\n<p>A quick google took me to\u00a0<a href=\"https:\/\/www.virustotal.com\" target=\"_blank\" rel=\"noopener\">VirusTotal<\/a> page.\u00a0 \u00a0 The website was really helpful and in no time I could know that the url had <span style=\"color: #ff0000;\">Malware<\/span>.\u00a0 I wonder all those who has Barclays cards and if they were compromised by clicking on the link :(.<\/p>\n<p>Learnings \/ warnings:<\/p>\n<ul>\n<li>Never open any email with attachments with un-known sources.<\/li>\n<li>Be sure to open only links with <span style=\"color: #008000;\">https<\/span> url.<\/li>\n<li>If you are specious about the link, do verify the link using a tool like <a href=\"https:\/\/www.virustotal.com\" target=\"_blank\" rel=\"noopener\">virustotal<\/a> before clicking it.<\/li>\n<\/ul>\n<p>And finally, keep your antivirus up-to date.<\/p>\n<p>[tweetthis remove_url=&#8221;true&#8221;]URL with Malware in pdf attachment[\/tweetthis]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I received an email from &#8220;Barclays &lt;ruman@antimbd.com&gt;&#8221; having subject &#8220;Account Alert &#8211; You have a new bill from Bank of America Credit Card&#8220;.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[184,179,181,182,183,180],"class_list":["post-561","post","type-post","status-publish","format-standard","hentry","category-general","tag-malicious-email-attachmenents","tag-malicious-links","tag-malware","tag-malware-attacks","tag-malware-attacks-via-email","tag-pushing-attacks"],"_links":{"self":[{"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/posts\/561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/comments?post=561"}],"version-history":[{"count":7,"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/posts\/561\/revisions"}],"predecessor-version":[{"id":568,"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/posts\/561\/revisions\/568"}],"wp:attachment":[{"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/media?parent=561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/categories?post=561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/btrnaidu.com\/index.php\/wp-json\/wp\/v2\/tags?post=561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}