Security News PowerPoint File Downloads Malware When You Hover a Link, No Macros Required

Nikos751

Level 20
Verified
Malware Tester
Feb 1, 2013
970
That's why it is called "Protected Mode" ;)
Security features are not a decoration nor just an annoying pop up.
Other than that, its an interesting malware that if existed in a different implementation with same result in other less protected programs it would be very dangerous.
 

In2an3_PpG

Level 18
Verified
Top Poster
Content Creator
Well-known
Nov 15, 2016
867
Well at least this attack is pretty much negated with the Office Protected View enabled at default.
 
  • Like
Reactions: brambedkar59

brambedkar59

Level 31
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
2,097
That's why it is called "Protected Mode" ;)
Security features are not a decoration nor just an annoying pop up.
Other than that, its an interesting malware that if existed in a different implementation with same result in other less protected programs it would be very dangerous.
To some users, the security features of an OS look like "decoration" and they disable them without even thinking. Some even think that OS updates are not necessary and they disable it, quite hastily.
Well at least this attack is pretty much negated with the Office Protected View enabled at default.
Or it would have been pretty big news, like Wannacry.
 

In2an3_PpG

Level 18
Verified
Top Poster
Content Creator
Well-known
Nov 15, 2016
867
Or it would have been pretty big news, like Wannacry.

That would of been interesting. Watch this will probably grow, maybe not near the extent of Wannacry but it will grow. You know there are some fools out there that probably disabled the protected view.
 
  • Like
Reactions: brambedkar59

brambedkar59

Level 31
Thread author
Verified
Top Poster
Well-known
Apr 16, 2017
2,097
That would of been interesting. Watch this will probably grow, maybe not near the extent of Wannacry but it will grow. You know there are some fools out there that probably disabled the protected view.
Yup, that would be interesting. Although I wouldn't care about it much because I use Office online and Google Docs. :)
 
  • Like
Reactions: In2an3_PpG

S3cur1ty 3nthu5145t

Level 6
Verified
May 22, 2017
251
The file is a PowerPoint presentation that is delivered to potential victims as a file attachment with emails bearing the subject line "RE: Purchase orders #69812" or "Fwd:Confirmation". The name of the PowerPoint file itself is "order&prsn.ppsx", "order.ppsx", or "invoice.ppsx", and there's also evidence the file has been spread around inside ZIP files.

First off, I would never open attachments from someone i did not know, and even those will be vetted for validity. Secondly, i leave "Protected Mode" enabled in MS office, so either way, this is really not an issue.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Good thing that it managed to block by MS Office Protected Mode, people should understand the benefits of a security protection including in downloading the security patches.

There is no surprise cause any functions can already implement with unknown execution of codes since hovering is one of many examples of a function.
 
  • Like
Reactions: brambedkar59

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top