{"id":79,"date":"2010-06-09T09:57:08","date_gmt":"2010-06-09T14:57:08","guid":{"rendered":"http:\/\/www.wilsonpr.com\/?p=79"},"modified":"2010-07-21T10:00:38","modified_gmt":"2010-07-21T15:00:38","slug":"red-condor-detects-sophisticated-one-two-punch-malware-campaign","status":"publish","type":"post","link":"https:\/\/www.wilsonpr.com\/?p=79","title":{"rendered":"Red Condor Detects Sophisticated One-Two Punch Malware Campaign"},"content":{"rendered":"<p><a href=\"http:\/\/www.redcondor.com\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-medium wp-image-8\" title=\"RedCondor logo red (sm)\" src=\"http:\/\/www.wilsonpr.com\/wp-content\/uploads\/2010\/03\/RedCondor-logo-red-sm-300x101.jpg\" alt=\"\" width=\"300\" height=\"101\" srcset=\"https:\/\/www.wilsonpr.com\/wp-content\/uploads\/2010\/03\/RedCondor-logo-red-sm-300x101.jpg 300w, https:\/\/www.wilsonpr.com\/wp-content\/uploads\/2010\/03\/RedCondor-logo-red-sm.jpg 535w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><a href=\"http:\/\/www.redcondor.com\/\">Red Condor<\/a> issued a warning of a new sophisticated email malware threat that spoofs YouTube and uses a redirect on a compromised website to a common Canadian Pharmacy web site to distribute malicious PDFs via drive-by download. The pharmacy page is actually a red herring that has distracted many security researchers from the true motive of these campaigns, a stealth drive-by download. With a single click, users can infect their computers.<\/p>\n<p>The malware, which as of the morning of June 9, 2010 had not been detected by any anti-virus engines, comes in the form of a malicious PDF download. Red Condor has captured 10 versions of the malicious PDF, which likely exploits vulnerabilities in Adobe Acrobat. The campaign appears to be part of a much larger attack first detected by Red Condor several weeks ago (see <a href=\"http:\/\/www.redcondor.com\/blog\/?p=161\">Red Condor blog entry April 23, 2010<\/a>) and has also recently spoofed Facebook and Twitter, among other popular brands.\u00a0As unsuspecting users wait for what they believe is a YouTube or Twitter friend request, a greeting card, or even a Facebook login page to load, their browsers download and execute the malicious code, and then the Canadian Pharmacy page appears.<\/p>\n<p><a href=\"http:\/\/www.marketwire.com\/press-release\/Red-Condor-Detects-Sophisticated-One-Two-Punch-Malware-Campaign-1273925.htm\" target=\"_blank\">Click here<\/a> to read the entire release.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Red Condor issued a warning of a new sophisticated email malware threat that spoofs YouTube and uses a redirect on a compromised website to a common Canadian Pharmacy web site to distribute malicious PDFs via drive-by download. The pharmacy page is actually a red herring that has distracted many security researchers from the true motive [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[23,24,4],"_links":{"self":[{"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=\/wp\/v2\/posts\/79"}],"collection":[{"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=79"}],"version-history":[{"count":2,"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=\/wp\/v2\/posts\/79\/revisions"}],"predecessor-version":[{"id":83,"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=\/wp\/v2\/posts\/79\/revisions\/83"}],"wp:attachment":[{"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=79"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=79"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wilsonpr.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=79"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}