Safety researcher Mahmoud Al-Qudsi noticed a âdrive-by-infectionâ hack on a compromised WordPress web page in which the scam was using JavaScript to adjust how textual content was exhibited on the web page, then urging buyers to obtain a resolve for the issue. Al-Qudsi reported, âThis attack gets a whole lot of points suitable that lots of some others fail at. The premise is essentially plausible: the textual content wonât render, and it says that is brought about by a lacking font, which it then prompts you to obtain and put in.â Screenshots clearly show a warning box developed by the hacker that seems genuine. A concept show says: âThe internet website page you are seeking to load is exhibited improperly as it utilizes the âHoefler Textâ font. To resolve the error and show the textual content, you have to update the âChrome Font Packâ.â By clicking on the âUpdateâ button, which sporting activities the correct colour blue that Chrome utilizes, a file called âChrome Font v7.5.1.exeâ downloads and the webpage morphs to âhelpfullyâ drive the person to operate the virus. This file is not recognised by either Windows Defender or Chrome as remaining a virus. Only 9 out of 59 antivirus scanners identify it as risky. If contaminated, VirusTotal unveiled the malware will snoop on files and documents and can be applied to examine main Windows technique files. Whilst Chrome wonât peg the file as remaining destructive, it is blocked by a warning that says âthis file isnât really downloaded pretty oftenâ. Tod Beardsley, analysis director at Rapid7 commented: âSo significantly, the assaults surface to be minimal to compromised WordPress internet sites â a area that is, regretably, loaded with targets.â âChrome buyers should really be conscious that genuine warnings from the Chrome browser will never ever surface as overlays to a internet website page. Specifically, Chrome does not offer you any performance for prompting for a lacking font obtain, and all such prompts are sourced from malware or malvertising campaigns. In the unusual conditions the browser wants to communicate a protection or misconfiguration warning to the person, these warnings will surface as a full, substitute website page, such as the familiar âYour link is not privateâ warning for misconfigured SSL certificates.â This write-up originally appeared at scmagazineuk.com
Supply url Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)
Related
Safety researcher Mahmoud Al-Qudsi noticed a âdrive-by-infectionâ hack on a compromised WordPress web page in which the scam was using JavaScript to adjust how textual content was exhibited on the web page, then urging buyers to obtain a resolve for the issue.
Al-Qudsi reported, âThis attack gets a whole lot of points suitable that lots of some others fail at. The premise is essentially plausible: the textual content wonât render, and it says that is brought about by a lacking font, which it then prompts you to obtain and put in.â
Screenshots clearly show a warning box developed by the hacker that seems genuine. A concept show says: âThe internet website page you are seeking to load is exhibited improperly as it utilizes the âHoefler Textâ font. To resolve the error and show the textual content, you have to update the âChrome Font Packâ.â
By clicking on the âUpdateâ button, which sporting activities the correct colour blue that Chrome utilizes, a file called âChrome Font v7.5.1.exeâ downloads and the webpage morphs to âhelpfullyâ drive the person to operate the virus.
This file is not recognised by either Windows Defender or Chrome as remaining a virus. Only 9 out of 59 antivirus scanners identify it as risky. If contaminated, VirusTotal unveiled the malware will snoop on files and documents and can be applied to examine main Windows technique files.
Whilst Chrome wonât peg the file as remaining destructive, it is blocked by a warning that says âthis file isnât really downloaded pretty oftenâ.
Tod Beardsley, analysis director at Rapid7 commented: âSo significantly, the assaults surface to be minimal to compromised WordPress internet sites â a area that is, regretably, loaded with targets.â
âChrome buyers should really be conscious that genuine warnings from the Chrome browser will never ever surface as overlays to a internet website page. Specifically, Chrome does not offer you any performance for prompting for a lacking font obtain, and all such prompts are sourced from malware or malvertising campaigns. In the unusual conditions the browser wants to communicate a protection or misconfiguration warning to the person, these warnings will surface as a full, substitute website page, such as the familiar âYour link is not privateâ warning for misconfigured SSL certificates.â
This write-up originally appeared at scmagazineuk.com