Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Colombo
Kaduwela - Two Storey House for Sale
dilrasan
Updated:
Thursday at 2:23 PM
Ad icon
Wechat qr verification
Pawan2005
Updated:
Thursday at 1:28 AM
🚀 GOOGLE AI PRO 18 MONTHS ACTIVATION 🚀
sayuru bandara
Updated:
Wednesday at 5:34 PM
Pure VPN - Up to 27 Months
vgp
Updated:
Jun 5, 2026
එක පැකේජ් එකයි මාසෙටම Unlimited Internet. තාමත් DATA CARD දාන්න සල්ලි වියදම් කරනවද? අඩුම මිලට අපෙන්.
sayuru bandara
Updated:
Jun 2, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
ElaKiri.com
News and Updates
Beware! This Microsoft PowerPoint
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="Sahitha" data-source="post: 21769970" data-attributes="member: 3335"><p><strong>Beware! Microsoft PowerPoint</strong></p><p></p><p style="text-align: center"><span style="font-size: 15px"><strong>Beware! This Microsoft PowerPoint Hack Installs Malware Without Requiring Macros</strong></span></p> <p style="text-align: center"></p> <p style="text-align: center"><img src="https://1.bp.blogspot.com/-UVQiTEP2tEg/WTfxDaHj79I/AAAAAAAAtCM/9Fh2KRn0Wn0wU7lyFSNRoV_QYesp-WA-gCLcB/s1600/microsoft-powerpoint-macros-malware.png" alt="" class="fr-fic fr-dii fr-draggable " style="" /></p><p></p><p></p><p></p><p><span style="font-size: 12px"><p style="text-align: center"><em>"Disable macros and always be extra careful when you manually enable it while opening Microsoft Office Word documents."</em></p></span></p><p style="text-align: center"><span style="font-size: 12px"></p></span></p><p style="text-align: center"><span style="font-size: 12px">You might have heard of above-mentioned security warning multiple times on the Internet as hackers usually leverage this decade old macros-based hacking technique to hack computers through specially crafted Microsoft Office files, particularly Word, attached to spam emails.</p></span></p><p style="text-align: center"><span style="font-size: 12px"></p></span></p><p style="text-align: center"><span style="font-size: 12px">But a new social engineering attack has been discovered in the wild, which doesn't require users to enable macros; instead it executes malware on a targeted system using PowerShell commands embedded inside a PowerPoint (PPT) file.</p></span></p><p style="text-align: center"><span style="font-size: 12px"></p></span></p><p style="text-align: center"><span style="font-size: 12px">Moreover, the malicious PowerShell code hidden inside the document triggers as soon as the victim moves/hovers a mouse over a link (as shown), which downloads an additional payload on the compromised machine -- even without clicking it.</p></span></p><p style="text-align: center"><span style="font-size: 12px"></p></span></p><p style="text-align: center"><span style="font-size: 12px">Researchers at Security firm SentinelOne have discovered that a group of hackers is using malicious PowerPoint files to distribute 'Zusy,' a banking Trojan, also known as 'Tinba' (Tiny Banker).</p></span></p><p style="text-align: center"><span style="font-size: 12px"></p></span></p><p style="text-align: center"><span style="font-size: 12px">Discovered in 2012, Zusy is a banking trojan that targets financial websites and has the ability to sniff network traffic and perform Man-in-The-Browser attacks in order to inject additional forms into legit banking sites, asking victims to share more crucial data such as credit card numbers, TANs, and authentication tokens.</p></span></p><p style="text-align: center"><span style="font-size: 12px"></p></span></p><p style="text-align: center"><span style="font-size: 12px"><em>"A new variant of a malware called 'Zusy' has been found in the wild spreading as a PowerPoint file attached to spam emails with titles like 'Purchase Order #130527' and 'Confirmation.' It's interesting because it doesn't require the user to enable macros to execute,"</em> researchers at SentinelOne Labs say in a blog post.</p></span></p><p style="text-align: center"><span style="font-size: 12px"></p></span></p><p style="text-align: center"><span style="font-size: 12px">The PowerPoint files have been distributed through spam emails with subjects like "Purchase Order" and "Confirmation," which when opened, displays the text "Loading...Please Wait" as a hyperlink.</p></span></p><p style="text-align: center"><span style="font-size: 12px"></p><p></span></p><p style="text-align: center"><img src="https://2.bp.blogspot.com/-GDEupOEqdmE/WTfiZdq-SlI/AAAAAAAAtB8/DuNyP7cruXgQPOz4Dwdr4cdVDAnhMPZ4ACLcB/s1600/microsoft-powerpoint-macros-malware.png" alt="" class="fr-fic fr-dii fr-draggable " style="" /></p> <p style="text-align: center"></p> <p style="text-align: center"></p> <p style="text-align: center"><span style="font-size: 12px">When a user hovers the mouse over the link it automatically tries to trigger the PowerShell code, but the Protected View security feature that comes enabled by default in most supported versions of Office, including Office 2013 and Office 2010, displays a severe warning and prompts them to enable or disable the content.</span></p> <p style="text-align: center"><span style="font-size: 12px"></span></p> <p style="text-align: center"><span style="font-size: 12px">If the user neglects this warning and allows the content to be viewed, the malicious program will connect to the "cccn.nl" domain name, from where it downloads and executes a file, which is eventually responsible for the delivery of a new variant of the banking Trojan called Zusy.</span></p> <p style="text-align: center"><span style="font-size: 12px"></span></p> <p style="text-align: center"><span style="font-size: 12px"><em>"Users might still somehow enable external programs because they're lazy, in a hurry, or they're only used to blocking macros," SentinelOne Labs says. "Also, some configurations may possibly be more permissive in executing external programs than they are with macros."</em></span></p> <p style="text-align: center"><span style="font-size: 12px"></span></p> <p style="text-align: center"><span style="font-size: 12px">Another security researcher, Ruben Daniel Dodge, also analyzed this new attack and confirmed that this newly discovered attack does not rely on Macros, Javascript or VBA for the execution method.</span></p> <p style="text-align: center"><span style="font-size: 12px"></span></p> <p style="text-align: center"><span style="font-size: 12px"><em>"This is accomplished by an element definition for a hover action. This hover action is setup to execute a program in PowerPoint once the user mouses over the text. In the resources definition of slide1 'rID2' is defined as a hyperlink where the target is a PowerShell command,"</em> Dodge said.</span></p> <p style="text-align: center"><span style="font-size: 12px"></span></p> <p style="text-align: center"><span style="font-size: 12px">The security firm also said that the attack doesn't work if the malicious file is opened in PowerPoint Viewer, which refuses to execute the program. But the technique could still be efficient in some cases.</span></p><p></p><p></p><p></p><p><span style="font-size: 12px"><strong>Mohit Kumar </strong> </span></p><p><span style="font-size: 12px">Entrepreneur, Hacker, Speaker, Founder and CEO — The Hacker News and The Hackers Conference.</span></p><p></p><p>Source - <a href="http://thehackernews.com/2017/06/microsoft-powerpoint-malware.html" target="_blank">The Hacker News /Microsoft-Powerpoint-Malware</a></p></blockquote><p></p>
[QUOTE="Sahitha, post: 21769970, member: 3335"] [b]Beware! Microsoft PowerPoint[/b] [CENTER][SIZE="4"][B]Beware! This Microsoft PowerPoint Hack Installs Malware Without Requiring Macros[/B][/SIZE] [IMG]https://1.bp.blogspot.com/-UVQiTEP2tEg/WTfxDaHj79I/AAAAAAAAtCM/9Fh2KRn0Wn0wU7lyFSNRoV_QYesp-WA-gCLcB/s1600/microsoft-powerpoint-macros-malware.png[/IMG][/CENTER] [SIZE="3"][CENTER][I]"Disable macros and always be extra careful when you manually enable it while opening Microsoft Office Word documents."[/I] You might have heard of above-mentioned security warning multiple times on the Internet as hackers usually leverage this decade old macros-based hacking technique to hack computers through specially crafted Microsoft Office files, particularly Word, attached to spam emails. But a new social engineering attack has been discovered in the wild, which doesn't require users to enable macros; instead it executes malware on a targeted system using PowerShell commands embedded inside a PowerPoint (PPT) file. Moreover, the malicious PowerShell code hidden inside the document triggers as soon as the victim moves/hovers a mouse over a link (as shown), which downloads an additional payload on the compromised machine -- even without clicking it. Researchers at Security firm SentinelOne have discovered that a group of hackers is using malicious PowerPoint files to distribute 'Zusy,' a banking Trojan, also known as 'Tinba' (Tiny Banker). Discovered in 2012, Zusy is a banking trojan that targets financial websites and has the ability to sniff network traffic and perform Man-in-The-Browser attacks in order to inject additional forms into legit banking sites, asking victims to share more crucial data such as credit card numbers, TANs, and authentication tokens. [I]"A new variant of a malware called 'Zusy' has been found in the wild spreading as a PowerPoint file attached to spam emails with titles like 'Purchase Order #130527' and 'Confirmation.' It's interesting because it doesn't require the user to enable macros to execute,"[/I] researchers at SentinelOne Labs say in a blog post. The PowerPoint files have been distributed through spam emails with subjects like "Purchase Order" and "Confirmation," which when opened, displays the text "Loading...Please Wait" as a hyperlink. [/CENTER][/SIZE] [CENTER][IMG]https://2.bp.blogspot.com/-GDEupOEqdmE/WTfiZdq-SlI/AAAAAAAAtB8/DuNyP7cruXgQPOz4Dwdr4cdVDAnhMPZ4ACLcB/s1600/microsoft-powerpoint-macros-malware.png[/IMG] [SIZE="3"]When a user hovers the mouse over the link it automatically tries to trigger the PowerShell code, but the Protected View security feature that comes enabled by default in most supported versions of Office, including Office 2013 and Office 2010, displays a severe warning and prompts them to enable or disable the content. If the user neglects this warning and allows the content to be viewed, the malicious program will connect to the "cccn.nl" domain name, from where it downloads and executes a file, which is eventually responsible for the delivery of a new variant of the banking Trojan called Zusy. [I]"Users might still somehow enable external programs because they're lazy, in a hurry, or they're only used to blocking macros," SentinelOne Labs says. "Also, some configurations may possibly be more permissive in executing external programs than they are with macros."[/I] Another security researcher, Ruben Daniel Dodge, also analyzed this new attack and confirmed that this newly discovered attack does not rely on Macros, Javascript or VBA for the execution method. [I]"This is accomplished by an element definition for a hover action. This hover action is setup to execute a program in PowerPoint once the user mouses over the text. In the resources definition of slide1 'rID2' is defined as a hyperlink where the target is a PowerShell command,"[/I] Dodge said. The security firm also said that the attack doesn't work if the malicious file is opened in PowerPoint Viewer, which refuses to execute the program. But the technique could still be efficient in some cases.[/SIZE][/CENTER] [SIZE="3"][B]Mohit Kumar [/B] Entrepreneur, Hacker, Speaker, Founder and CEO — The Hacker News and The Hackers Conference.[/SIZE] Source - [URL="http://thehackernews.com/2017/06/microsoft-powerpoint-malware.html"]The Hacker News /Microsoft-Powerpoint-Malware[/URL] [/QUOTE]
Insert quotes…
Verification
Winadiyakata thappara keeyak tibeda?
Post reply
Top
Bottom