Site icon WinCert

PowerPoint files are threatening again?

<p>Internet security is one of the most important aspects of any online activity&period; The more you use it&comma; the more vulnerable you become and cyber criminals are aware of that&period;<&sol;p>&NewLine;<p>So whether you use it only for private matters or you use it for business&comma; caution should always be your primary source of defense&period;<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2017&sol;03&sol;office-1356793&lowbar;640&period;png"><img class&equals;"alignnone size-full wp-image-2053" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2017&sol;03&sol;office-1356793&lowbar;640&period;png" alt&equals;"office&semi; powerpoint" width&equals;"640" height&equals;"452" &sol;><&sol;a><&sol;p>&NewLine;<p>The latest attack on online security is no exception&period; In most cases&comma; cyber criminals carefully plan their strategy and a way into your computer and your privacy&period;<&sol;p>&NewLine;<h4>This time they are using Windows Object Linking Interface in PowerPoint&comma; which is the technology that allows exporting part of a document with a different editing application than the original&period;<&sol;h4>&NewLine;<p>PowerPoint and its usage are very common and most people with only basic computer knowledge know how to use PowerPoint&period; Moreover&comma; that is the most vulnerable group because they suspect nothing and very often they click and open any kind of document that they receive&period;<&sol;p>&NewLine;<p>PowerPoint presentations which they receive in their emails are especially dangerous&period; Users might receive what seems like a harmless email or people that are used to online shopping might receive an attachment with shipping details&period; Unsuspectingly&comma; they open the email and&sol;or attachment&comma; inviting the malware on your computer&period;<&sol;p>&NewLine;<p>When the PPSX file is opened&comma; &OpenCurlyQuote;CVE-2017-8570’ is displayed&period; The CVE-2017-0199 Remove Code Execution will then run a process to download logo&period;com to the computer which then runs a command to download RATMAN&period;exe&period; RATMAN&period;exe makes a connection to the Command and Control server&comma; and since it is a tool for remote control&comma; users will not be aware of it&period; It is very dangerous because it allows the cyber criminals a direct link to the computer and almost everything on it&period;<&sol;p>&NewLine;<p>So extra caution is needed when downloading attachments from unknown sources&period;<&sol;p>&NewLine;

Exit mobile version