Showing posts with label vir-Troj/PDFJs-II. Show all posts
Showing posts with label vir-Troj/PDFJs-II. Show all posts

Tuesday, May 11, 2010

May 11 CVE-2010-0188 PDF Call the Ministry of Defense from hiw11111@gmail.com

Download ATT73189.pdf aaeed3399e542e4ba881f27adabaf31f ac as a password protected archive (please contact me for the password if you need it)

Details ATT73189.pdf aaeed3399e542e4ba881f27adabaf31f 

From: yiwei huang [mailto: hiw11111@gmail.com]Sent: Tuesday, May 11, 2010 9:06 PMTo: XXXXXXSubject: Call the Ministry of DefenseSuch as the subject

-Coast Guard Department of Planning by Wei HuangTEL: 02-22399201 # 266137FAX: 02-22392936Wenshan District, Taipei City 296, Sec Xinglong



File ATT73189.pdf received on 2010.05.12 12:35:03 (UTC)
Result: 7/41 (17.08%)
Authentium    5.2.0.5    2010.05.12    JS/Pdfka.AD
Avast    4.8.1351.0    2010.05.12    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.05.12    PDF:CVE-2010-0188
ClamAV    0.96.0.3-git    2010.05.12    Suspect.PDF.ObfuscatedJS
GData    21    2010.05.12    PDF:CVE-2010-0188
IMicrosoft    1.5703    2010.05.12    Exploit:Win32/Pdfjsc.FI
Sophos    4.53.0    2010.05.12    Troj/PDFJs-II
Additional information
File size: 446746 bytes
MD5...: aaeed3399e542e4ba881f27adabaf31f

:CVE-2010-0188


Thursday, May 6, 2010

May 6 CVE-2010-0188 PDF birthday briefing series from spoofed jjsung@ntu.edu.tw

Download  d80eb21cfe8ad1a710c8652b13f8b7 ATT59802.pdf ac as a password protected archive (please contact me for the password if you need it)



Virustotal
 File ATT59802.pdf received on 2010.05.06 18:49:42 (UTC)
Result: 6/41 (14.64%)
Avast    4.8.1351.0    2010.05.06    PDF:CVE-2010-0188
Avast5    5.0.332.0    2010.05.06    PDF:CVE-2010-0188
eTrust-Vet    35.2.7471    2010.05.06    PDF/CVE-2010-0188!exploit
Kaspersky    7.0.0.125    2010.05.06    Exploit.Win32.Pidief.dch
Sophos    4.53.0    2010.05.06    Troj/PDFJs-II
Additional information
File size: 106855 bytes6
MD5...: d80eb21cfe8ad1a710c8652b13f8b7ac


 

-----Original Message-----
From: jjsung@ntu.edu.tw [mailto:jjsung@ntu.edu.tw]
Sent: 2010-05-06 10:34 AM
To: XXXXXXXXXXXX
Subject: 蔡政文教授七十華誕系列活動簡報

XXXXXXXXXXXXX

今年適逢我國政治學界耆老、臺大政治學系名譽教授、國策顧問、國家政策研究基金會執行長蔡政文教授七秩華誕,為祝賀蔡教授七秩榮慶,及表達國內政治學同道景仰之意,籌委會特別規劃系列活動,以玆慶賀。
一、蔡政文教授七十華誕學術論文研討會
謹訂於今年5月29、30兩日假台大社科院國際會議廳舉辦「全球、兩岸、臺灣—蔡政文教授七十華誕學術論文研討會」,此次研討會主題訂為「全球、兩岸、臺灣」,也正呼應馬總統「壯大臺灣、連結兩岸、布局全球」的整體大戰略,歡迎蔡教授的門生故舊與知交友好踴躍賜稿外,亦請政治學先進與同道惠賜宏文,共襄盛舉。
二、大陸地區賀壽團來訪
為擴大參與並推動兩岸學術交流,探討「壯大臺灣、連結兩岸、布局全球」之當前國家發展方針,藉此加速大陸民主化之進程,同時邀集與蔡老師有深厚情誼的江蘇省海峽兩岸關係研究會、中國社科院台灣研究所等重要涉台智庫組團來臺祝賀,共襄盛舉。與會大陸學者除參與論文研討會外,會後並安排大陸學者南下參訪政經建設。
來臺賀壽團名單:
江蘇省海峽兩岸關係研究會:路進明副會長暨夫人
台研所:朱副所長衛東、田主任賀民、高劍副主任、柳英助理研究員、汪助理研究員曙申、陳助理研究員詠江等六人
南京大學:張永桃副校長(中國政治學會副會長)、張鳳陽院長
三、蔡政文教授七十華誕祝壽晚宴
預定於99年5月29日(星期六)晚上六點舉行,晚宴席設上海鄉村首都店。
蔡老師自民國63年指導學生林嘉誠撰寫〈大衛‧伊士頓之政治理論〉碩士論文起,截至99年4月底,指導學生共計有25位博士、98位碩士。
蔡老師的每位指導學生,畢業後都能謹遵師訓,在工作崗位上有傑出的表現,未曾辜負老師的嚴格訓練。
蔡老師的門生、故舊、同事、部屬都期盼能躬逢其盛,為蔡老師舉辦一場祝壽晚宴,以表達心中的感謝與祝福!

----------------------------------------------------------------------
若有任何垂詢事項,請洽:
籌委會總幹事  宋紀均
電話:0932-322-687;傳真:(02) 2367-9708;
電子信箱:jjsung@ntu.edu.tw
----- Original Message -----From: jjsung@ntu.edu.tw [mailto: jjsung@ntu.edu.tw]Sent: 2010-05-06 10:34 AMTo: XXXXXXSubject: Professor Cai Zhengwen 70 birthday briefing seriesXXXX Hello:This year marks the country's political circles and seniors, National Taiwan University political science professor emeritus, national policy advisor to the National Policy Research Foundation, Professor Cai Zhengwen Seventieth Birthday, Professor Zhu Hecai seven to rank Rongqing, and expression of admiration of fellow domestic politics means , the PC series of special planning activities to celebrate hereby.First, Professor Cai Zhengwen 70 birthday academic seminarTo be held May 29-30 this year, a two-day leave held at National Taiwan University International Conference Hall, Academy of Social Sciences, "global, cross-strait, Taiwan - 70 birthday of Professor Cai Zhengwen academic seminar", the theme of the seminar as a "global, cross-strait , Taiwan ", are also echoed President Ma of" strengthening Taiwan, connecting both sides of the layout of the world, "the overall grand strategy, welcomed Professor Cai friendly and enthusiastic disciple old friends and fraternity grant the draft, but also advanced and fellow political science please give Wang Hui Wen, join the festivities.Second, the mainland delegation's visit Birthday GreetingsTo expand the participation and promote cross-strait academic exchanges, of "strengthening Taiwan, connecting both sides of the layout of the world" in the current national development policy to accelerate the democratization process in mainland China, and invited Tsai has a profound friendship with the Jiangsu Province-Strait Relations Research Council, the Chinese Academy of Social Sciences Institute of Taiwan Studies, and other important Taiwan-related think tanks to organize groups to congratulate the endeavor. In addition to participating scholars from mainland China to participate thesis seminars will be arranged after visiting mainland scholars south political and economic development.Taiwan Yoshihisa group list:Jiangsu Province of cross-strait relations will be: Way into the next vice chairman and his wifeTaiwan Research Institute: Deputy Director Zhu Weidong, landowner Renhe Min, Gao Jian, deputy director, Liu Ying, an assistant researcher, assistant researcher Wang Shu Shen, Yong Jiang Dengliu Ren Chen, an assistant researcherNanjing: Zhang Tao, Vice President (Vice President of Chinese Political Science Association), Zhang Fengyang DeanThird, Professor Cai Zhengwen 70 birthday birthday dinnerScheduled for 5 月 29 日 99 (星期六) 18:00 held a dinner I set up shop in Shanghai Rural capital.Tsai guide students from the Republic of China Lin Chia-cheng 63 years to write master's thesis on, at 99 years by the end of April, guiding students to a total of 25 doctoral, 98 master's degree.Tsai's guide for each student upon graduation can Jinzun teacher training, in the workplace have outstanding performance, did not live up to the rigorous training of teachers.Tsai's disciple, and old friends, colleagues, subordinates all look forward to critical keepers, to host a birthday dinner Tsai, to express their thanks and best wishes!-------------------------------------------------- --------------------If you have any inquiries matters, please contact:Director-General of the Preparatory Committee of Song Ji areTel :0932-322-687; Fax: (02) 2367-9708;E-mail: jjsung@ntu.edu.tw

 Headers
Received: from wmail1.cc.ntu.edu.tw (HELO wmail1.cc.ntu.edu.tw) (140.112.2.161)
  by XXXXXXXwith DHE-RSA-AES256-SHA encrypted SMTP; 6 May 2010 14:33:45 -0000
Received: from localhost (localhost [127.0.0.1])
    by wmail1.cc.ntu.edu.tw (Postfix) with ESMTP id 9DABE35E841
    for XXXXXXXXX; Thu,  6 May 2010 22:33:42 +0800 (CST)
Received: from 218.94.121.180 ([218.94.121.180]) by wmail1.cc.ntu.edu.tw
 (Horde Framework) with HTTP; Thu, 06 May 2010 22:33:42 +0800
Message-ID: <20100506223342.59074hzo2e1mojly@wmail1.cc.ntu.edu.tw>
Date: Thu, 6 May 2010 22:33:42 +0800
Disposition-Notification-To: jjsung@ntu.edu.tw
From: jjsung@ntu.edu.tw




Hostname:    218.94.121.180
ISP:    Data Communication Division
Organization:    CHINANET jiangsu province network
Country:    China cn flag
State/Region:    Beijing
City:    Beijing

Friday, April 30, 2010

Apr 30 CVE-2010-0188 PDF North Korea's Radio Waves of Resistance fromdavidaustin3@yahoo.com

Details 2b4b5e0ce5a19d81ea918f50f56ff8d0 North_Korea_update.pdf 


From: David Austin [mailto:davidaustin3@yahoo.com]
Sent: Friday, April 30, 2010 2:00 AM
To: XXXXXXXXXXXXX
Subject: North Korea's Radio Waves of Resistance
Importance: Low
North Korea's Radio Waves of Resistance

By Peter M. Beck | April 27, 2010

North Korea remains the most isolated country on earth, with its people
effectively cut off from the outside world?or so the world has been told.
But there is reason to believe this is no longer the case. My research
suggests millions of North Koreans listen to or hear about foreign radio
broadcasts. There is evidence the numbers are growing.

Attachments
     http://www.virustotal.com/analisis/a967a1523f859cfbd69de0d5f9f70228e100ec9d7bf07066cbfb206b8e4d4b23-1272627594
     File North_Korea_update.pdf received on 2010.04.30 11:39:54 (UTC)
    Result: 13/40 (32.5%)
    AhnLab-V3    2010.04.30.02    2010.04.30    PDF/Cve-2010-0188
    Avast    4.8.1351.0    2010.04.30    PDF:CVE-2010-0188
    Avast5    5.0.332.0    2010.04.30    PDF:CVE-2010-0188
    AVG    9.0.0.787    2010.04.30    Exploit_c.DEY
    BitDefender    7.2    2010.04.30    Exploit.PDF-EXE.Gen
    DrWeb    5.0.2.03300    2010.04.30    Exploit.PDF.758
    eSafe    7.0.17.0    2010.04.29    PDF.Exploit
    F-Secure    9.0.15370.0    2010.04.30    Exploit.PDF-EXE.Gen
    GData    21    2010.04.30    Exploit.PDF-EXE.Gen
    Rising    22.45.04.03    2010.04.30    Hack.Exploit.PDF.aem
    Sophos    4.53.0    2010.04.30    Troj/PDFJs-II
    Sunbelt    6241    2010.04.30    Exploit.PDF.CVE-2010-0806 (v)  - Sunbelt, this is a wrong name
    VirusBuster    5.0.27.0    2010.04.29    JS.Crypt.UQBF
    Additional information
    File size: 240872 bytes
    MD5...: 2b4b5e0ce5a19d81ea918f50f56ff8d0

    Received: from [123.125.156.138] by web114410.mail.gq1.yahoo.com via HTTP; Thu, 29 Apr 2010 22:59:34 PDT
    X-Mailer: YahooMailRC/348.5 YahooMailWebService/0.8.103.269680
    Date: Thu, 29 Apr 2010 22:59:34 -0700
    From: David Austin
    Subject: North Korea's Radio Waves of Resistance


          Hostname:    123.125.156.138
          ISP:    China Unicom Beijing Province Network
          Organization:    China Unicom Beijing Province Network
          Proxy:    Suspected network sharing device.
          Country:    China
          State/Region:    Beijing
          City:    Beijing
    http://www.robtex.com/ip/123.125.156.138.html#whois

    inetnum: 123.112.0.0 - 123.127.255.255
    netname: UNICOM-BJ
    descr: China Unicom Beijing province network
    descr: China Unicom
    country: CN
    admin-c: CH1302-AP
    tech-c: SY21-AP
    mnt-by: APNIC-HM
    mnt-lower: MAINT-CNCGROUP-BJ
    mnt-routes: MAINT-CNCGROUP-RR
    status: ALLOCATED PORTABLE
    person: ChinaUnicom Hostmaster
    nic-hdl: CH1302-AP
    e-mail: abuse@chinaunicom.cn
    address: No.21,Jin-Rong Street
    address: Beijing,100140
    address: P.R.China
    phone: +86-10-66259940
    fax-no: +86-10-66259764
    country: CN
    changed: abuse@chinaunicom.cn 20090408
    mnt-by: MAINT-CNCGROUP
    source: APNIC

    person: sun ying
    address: fu xing men nei da jie 97, Xicheng District
    address: Beijing 100800
    country: CN
    phone: +86-10-66030657
    fax-no: +86-10-66078815
    e-mail: hostmast@publicf.bta.net.cn
    nic-hdl: SY21-AP
    mnt-by: MAINT-CNCGROUP-BJ
    changed: suny@publicf.bta.net.cn 19980824
    changed: hm-changed@apnic.net 20060717
    changed: hostmast@publicf.bta.net.cn 20090630
    source: APNIC

    Thursday, April 29, 2010

    Apr 26 CVE-2010-0188 PDF North Korea Policy Piece from (fake) walterkeats@yahoo.com

    Download  4fcc7b56fdc488a333f3d97ad502eb22 20100426_WLK_Position_Paper.pdf as a password protected archive (please contact me for the password if you need it)


    Details 4fcc7b56fdc488a333f3d97ad502eb22 20100426_WLK_Position_Paper.pdf 


    From: Keats, Walter 
    [mailto:walterkeats@yahoo.com]
    Sent: Monday, April 26, 2010 9:53 AM
    To: XXXXXXXXXXXXXX
    Subject: North Korea Policy Piece

    XXXXX

    I was able to visit the DPRK in February, my 20th trip, demonstrating that Americans can now visit the DPRK year round.  The most significant new thing I did this trip was to visit Sinchon where there was a massacre in the fall of 1950.  Pretty gruesome, but not clear who did what to whom.  I also got to see the Pyongyang Golf Club, although it was snow covered, among other sites in the Pyongyang area.

    At any rate, I have written the attached opinion piece, not for publication or attribution, to see what you and others think about it.  Let me know at your convience.

    Best regards,

    Walter

    Walter L. Keats, CTC, CMP
    President
    Asia Pacific Travel, Ltd.
    P.O. Box 350
    Kenilworth, IL 60043-0350 USA

    Celebrating 30 years of designing memorable custom individual and small group tours to East Asia for discerning clients.

    The only American company directly authorized by North Korea to arrange for tourists from America and other countries to visit the DPRK.

    Header info
    Received: from [204.12.252.250] by web114508.mail.gq1.yahoo.com via HTTP; Mon, 26 Apr 2010 06:53:11 PDT
    X-Mailer: YahooMailClassic/10.1.9 YahooMailWebService/0.8.102.267879
    Date: Mon, 26 Apr 2010 06:53:11 -0700
    From: "Keats, Walter"

         204.12.192.0/18     AS32097
    RoadRunner RR-RC-Wholesale Internet, Inc.-KansasCity
    WholeSale Internet, Inc. WHOLESALEINTERNET-3 (NET-204-12-192-0-1)
    204.12.192.0 - 204.12.255.255
    Daigou Inc. WII-2197-10075602 (NET-204-12-252-248-1)
    204.12.252.248 - 204.12.252.255

    File 20100426_WLK_Position_Paper.pdf received on 2010.04.29 04:24:04 (UTC)
    Result: 6/41 (14.64%)
    Avast    4.8.1351.0    2010.04.28    PDF:CVE-2010-0188
    Avast5    5.0.332.0    2010.04.28    PDF:CVE-2010-0188
    ClamAV    0.96.0.3-git    2010.04.29    Exploit.PDF-22668
    eTrust-Vet    35.2.7456    2010.04.28    PDF/CVE-2010-0188!exploit
    GData    21    2010.04.29    PDF:CVE-2010-0188
    Sophos    4.53.0    2010.04.29    Troj/PDFJs-II
    Additional information
    File size: 44661 bytes
    MD5...: 4fcc7b56fdc488a333f3d97ad502eb22




    Saturday, April 10, 2010

    Apr 10 CVE-2010-0188 PDF Research Paper on Nuclear Posture Review 2010 and the upcoming Nuclear Security Summit

    Download  Research Paper on Nuclear Posture Review 2010.PDF 8ae20aabfb207f5bb4e3918b043d37fa as a password protected archive (please contact me if you need the password)

    Details Research Paper on Nuclear Posture Review 2010.PDF 8ae20aabfb207f5bb4e3918b043d37fa

    Ok, let's see - the Nuclear Summit starts in DC on Monday



    From: [Redacted]@yahoo.com;
    Date: Sat, Apr 10, 2010 at 10:02 AM
    Subject: [Redacted] Research Paper on Nuclear Posture Review 2010 and the upcoming Nuclear Security Summit
    To: [Redacted]

    Dear Sir/Madam,

    The 2010 Nuclear Posture Review (NPR) outlines the Administration’s approach to promoting the President’s agenda for reducing nuclear dangers and pursuing the goal of a world without nuclear weapons, while simultaneously advancing broader U.S. security interests.

    According to the White House, the end goal of the upcoming Nuclear Security Summit 2010 will be “a communiqué pledging efforts to attain the highest levels of nuclear security, which is essential for international security as well as the development and expansion of peaceful nuclear energy worldwide.”

    Accompanying this letter is the [Redacted]Research Paper on Nuclear Posture Review 2010 and the upcoming Nuclear Security Summit. Please let us know whether you find it useful, and whether there is additional information you would like to see included in future editions. We very much value your support and assistance.


    [Redacted address and signature]

    Header info
    Sender  174.139.92.6

    Thursday, March 25, 2010

    Mar 25 CVE-2010-0188 PDF Re: conference memo from jesseandy2@gmail.com


    Download  c9c89ebc508c783defe7042eb9c0e5cc conference memo.PDF and all files below as a password protected archive (please contact me if you need the password)

    Details c9c89ebc508c783defe7042eb9c0e5cc conference memo.PDF 

    This is a fake conversation - it is a semi interesting social engineering trick.
     
    From: Lee [mailto:jesseandy2@gmail.com]
    Sent: Thursday, March 25, 2010 11:11 PM
    To: XXXXXXXXXXXXXX
    Subject: Re: conference memo

    Who are you?What do you mean?.This conference memo  is nothing with me.

    On Thu, Mar 25, 2010 at 4:46 PM,  wrote:
     
    Hey,this is the last conference memo, After reading it ,pls send it to Mr Francis,and delete this mail ASAP.

    Lee


    Virustotal report
    http://www.virustotal.com/analisis/49cefe07c61ddce14b2eea7c64a5bc2a97e29e0bbdd0cd52832a1dff0369a523-1269796247
     File conference_memo.PDF received on 2010.03.28 17:10:47 (UTC)
    Result: 4/42 (9.53%)
    F-Secure    9.0.15370.0    2010.03.28    Exploit:W32/Pidief.CNF
    PCTools    7.0.3.5    2010.03.28    HeurEngine.Pdexe
    Sophos    4.52.0    2010.03.28    Troj/PDFJs-II
    Symantec    20091.2.0.41    2010.03.28    Trojan.Pidief.I
    File size: 76137 bytes
    MD5...: c9c89ebc508c783defe7042eb9c0e5cc

    parsed with pdf-parser.py  





    Wednesday, March 24, 2010

    Mar 24 CVE-2010-0188 PDF rumours in N Korea2010march from coljoint@aol.com


    Download 3fe225e4f42dad6a4c4863291f532dd2 rumours_in_N_Korea2010march.pdf as a password protected archive (please contact me if you need the password) 

    Details 3fe225e4f42dad6a4c4863291f532dd2 rumours_in_N_Korea2010march.pdf 

    From: coljoint@aol.com [mailto:coljoint@aol.com]
    Sent: Wednesday, March 24, 2010 9:30 AM
    To: coljoint@aol.com
    Subject: rumours in N Korea2010march
    Importance: Low

    Hi:
    Some rumours suggested that the recent currency reform was associated with Kim Jong-eun.  The attachments are dealt greatly with succession issues and situation in N Korea.
       Best regards
    File rumours_in_N_Korea2010march.pdf received on 2010.03.30 11:43:02 (UTC)
    http://www.virustotal.com/analisis/038c36b2f2f4404828a4c5881037d7be5e3373a4ab1ac2e8b2c49a021d22fcf0-1269949382
    Result: 4/42 (9.53%)
    ClamAV    0.96.0.0-git    2010.03.30    Exploit.PDF-17840
    PCTools    7.0.3.5    2010.03.30    HeurEngine.Pdexe
    Sophos    4.52.0    2010.03.30    Troj/PDFJs-II
    Symantec    20091.2.0.41    2010.03.30    Trojan.Pidief.I
    Additional information
    File size: 191651 bytes
    MD5...: 3fe225e4f42dad6a4c4863291f532dd2

    parsed with pdf-parser.py  



    Mar 24 CVE--2010-0188 PDF My application from donald932@gmail.com



    From: Huang [mailto:donald932@gmail.com]
    Sent: Wednesday, March 24, 2010 4:26 AM
    To: XXXXXXXXXXXX
    Subject: : My application

    This is my application, please check it appropriate or not, and
    looking forward for your reply.
    Huang

    Virustotal
    http://www.virustotal.com/analisis/dc29830cd35d8cf60df907c101daf05ad14111fa63c8071fd8f7465be2825968-1270006579
     File application.PDF received on 2010.03.31 03:36:19 (UTC)
    Result: 5/42 (11.91%)
    ClamAV    0.96.0.0-git    2010.03.30    Exploit.PDF-17705
    F-Secure    9.0.15370.0    2010.03.31    Exploit:W32/Pidief.CND
    PCTools    7.0.3.5    2010.03.31    HeurEngine.Pdexe
    Sophos    4.52.0    2010.03.31    Troj/PDFJs-II
    Symantec    20091.2.0.41    2010.03.31    Trojan.Pidief.I
    Additional information
    File size: 57116 bytes
    MD5...: 76f7e8dc68b364abfd893f0e9340fae8





    %user%\Local Settings\Temp\application.PDF
    %user%\Local Settings\Temp\temp.tmp
    %user%\Local Settings\Temp\xxx.exe
    %user%\Temp\~.exe
    %user%\help.dll



    http://www.virustotal.com/analisis/60505da8832dd0f0d737e9793c8240185e00a1b44ac5ef4383e0d86bf5d97d71-1270010048
    File help.dll received on 2010.03.31 04:34:08 (UTC)
    Result: 4/36 (11.11%)
    DrWeb 5.0.2.03300 2010.03.31 Trojan.LydraSpy.origin
    Panda 10.0.2.2 2010.03.30 Suspicious file
    Sophos 4.52.0 2010.03.31 Sus/Behav-113
    Symantec 20091.2.0.41 2010.03.31 Suspicious.Insight
    File size: 101376 bytes
    MD5   : e868c642ed4040f0e6752fe427084d3d




    all other files and connections are like in this post Mar 25 CVE-2010-0188 PDF Re: conference memo from jesseandy2@gmail.com




    Monday, March 8, 2010

    Mar 8 CVE-2010-0188 PDF China to participate in cross-strait relations seminar from spoofed titx@oa.tku.edu.tw

    Details _.pdf - cdb5e82e4d07911f9add5cdcf817e9ed


    From: 國際事務與戰略研究所 [mailto:titx@oa.tku.edu.tw]
    Sent: Monday, March 08, 2010 8:54 PM
    To: XXXXX
    Subject: 敬邀參加兩岸關系研討會

    From: International Affairs and Strategic Studies [mailto: titx@oa.tku.edu.tw]Sent: Monday, March 08, 2010 8:54 PMTo: XXXXXSubject: China to participate in cross-strait relations seminar

    Header info
    Received: from IBM-62979760B13 ([211.75.147.173])
        by msr39.hinet.net (8.9.3/8.9.3) with ESMTP id JAA10998
        for XXXXXXXXXXX Tue, 9 Mar 2010 09:53:32 +0800 (CST)
    Reply-To: titx@oa.tku.edu.tw
    From: "=?BIG5?B?sOq72qjGsMi7UL7UsqSs46hzqdI=?="

          Hostname:    mx3.imedia.com.tw
          ISP:    CHTD, Chunghwa Telecom Co., Ltd.
          Organization:    Ming Siang Printing Co., Ltd.
          Country:    Taiwan
          State/Region:    T'ai-pei
          City:    Taipei


    Virustotal scans
    Scan 1
     File _.pdf received on 2010.03.09 16:54:40 (UTC)
    http://www.virustotal.com/analisis/be7578591f45418541d1e38b9389b3e35063a1cd61c1db489bac08e944bce258-1268153680
    Result: 5/42 (11.90%)
    eSafe     7.0.17.0     2010.03.09     PDF.Exploit
    McAfee     5914     2010.03.08     Exploit-PDF.q.gen!stream
    McAfee+Artemis     5915     2010.03.09     Exploit-PDF.q.gen!stream
    Microsoft     1.5502     2010.03.09     Exploit:Win32/Pidief.AY
    Additional information
    File size: 80199 bytes
    MD5   : cdb5e82e4d07911f9add5cdcf817e9ed


    Scan 2
    http://www.virustotal.com/analisis/be7578591f45418541d1e38b9389b3e35063a1cd61c1db489bac08e944bce258-1269343175

     File _.pdf received on 2010.03.23 11:19:35 (UTC)
    Result: 24/42 (57.15%)
    a-squared    4.5.0.50    2010.03.23    Exploit.JS.Pdfka!IK
    AhnLab-V3    5.0.0.2    2010.03.23    PDF/Cve-2010-0188
    AntiVir    8.2.1.196    2010.03.23    EXP/Pidief.bui
    Antiy-AVL    2.0.3.7    2010.03.23    Exploit/JS.Pdfka
    Authentium    5.2.0.5    2010.03.23    JS/ShellCode.AM
    AVG    9.0.0.787    2010.03.23    Exploit_c.DEY
    BitDefender    7.2    2010.03.23    Exploit.PDF-EXE.Gen
    DrWeb    5.0.1.12222    2010.03.23    Exploit.PDF.758
    eSafe    7.0.17.0    2010.03.21    PDF.Exploit
    eTrust-Vet    35.2.7383    2010.03.23    PDF/Pidief.PR
    F-Secure    9.0.15370.0    2010.03.23    Exploit.PDF-EXE.Gen
    GData    19    2010.03.23    Exploit.PDF-EXE.Gen
    Ikarus    T3.1.1.80.0    2010.03.23    Exploit.JS.Pdfka
    Kaspersky    7.0.0.125    2010.03.23    Exploit.JS.Pdfka.bui
    McAfee    5928    2010.03.22    Exploit-PDF.by
    McAfee+Artemis    5928    2010.03.22    Exploit-PDF.by
    McAfee-GW-Edition    6.8.5    2010.03.23    Exploit.Pidief.bui
    Microsoft    1.5605    2010.03.23    Exploit:Win32/Pdfjsc.gen!B
    Rising    22.40.01.04    2010.03.23    Hack.Exploit.PDF.aem
    Sophos    4.51.0    2010.03.23    Troj/PDFJs-II
    Sunbelt    6031    2010.03.22    Exploit.PDF.CVE-2010-0806 (v)  - nope, it is not (M)
    Symantec    20091.2.0.41    2010.03.23    Trojan.Pidief.I
    TrendMicro    9.120.0.1004    2010.03.23    TROJ_PDFKA.AR
    VirusBuster    5.0.27.0    2010.03.22    JS.Crypt.UQBF
    Additional information
    File size: 80199 bytes
    MD5...: cdb5e82e4d07911f9add5cdcf817e9ed


    Wepawet
    benign
    http://wepawet.cs.ucsb.edu/view.php?hash=cdb5e82e4d07911f9add5cdcf817e9ed&type=js