Common Vulnerabilities and Exposures
CVE-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010.
General File Information
MD5 8E633588B3EE59DE09FE126D99869D2D
SIZE 103981 bytes
EXPLOIT TYPE CVE-2010-2883
FILE NAME Bin Ladens successor.pdf
EXPLOIT TYPE CVE-2010-2883
FILE NAME Bin Ladens successor.pdf
Post Updates
The file uses Fonts/SING CVE_2010-2883 exploit, which does not seem to be metasploit generated.
* Jan 12 CVE-2010-3654 + CVE-2009-4324 + CVE-2009-0927 + CVE-2008-0655 PDF JANUARY 2011 from a compromised Thai Police account
The sender is often uses compromised servers of different organizations
* Jan 6 CVE-2010-3333 DOC with info theft trojan from the American Chamber of Commerce* Jan 12 CVE-2010-3654 + CVE-2009-4324 + CVE-2009-0927 + CVE-2008-0655 PDF JANUARY 2011 from a compromised Thai Police account
It is unclear whether this time it is a compromised server or the attacker uses the services of this internet provider as a customer
Beyond the Network America, Inc. (BTNaccess) is a wholly owned subsidiary of PCCW, and is headquartered in Reston, Virginia and Hong Kong with offices in Los Angeles, New York City, Philadelphia, Houston, London, Moscow, Prague, Kuala Lumpur, Singapore, Shenzhen, Tokyo, Mumbai and New Delhi.
PCCW, a global leader in next generation broadband solutions, is the largest telecommunications provider in Hong Kong. PCCW is the operator of one of the world’s most advanced broadband networks and has over 700,000 broadband customers and 12,500 employees worldwide. As a global player, PCCW has portrayed innovation within the industry and demonstrated financial stability with 2003 revenues reaching US$2.89 billion.