Author Topic: Attacked 28 May 2018 - TTF:CVE - 2015-2426 [Exp1]  (Read 1332 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Attacked 28 May 2018 - TTF:CVE - 2015-2426 [Exp1]
« on: May 28, 2018, 07:27:35 PM »

Why didn't Avast catch this before it infected my computer?
I tried to look at a page for Costa Rican coffee called "Montana"
I first looked at their FB page, but when I followed the link to their website, suddenly a page popped up, with threatening voice and information, telling me that my machine had been attacked and to call some number within 5 minutes.
I did NOT call.
Instead, I turned off the computer and unplugged the modem.
Then I ran an Avast boot scan.  It showed nothing. 
When I ran a second Avast boot scan, it found and quarantined TTF:CVE - 2015 - 2426 [Exp1]
My questions now:
- Is my computer safe now?
- Why didn't Avast catch the TTF:CVE before I landed on the page that held it?
- Why didn't the first boot scan catch the virus?
- What else should I do now?


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Attacked 28 May 2018 - TTF:CVE - 2015-2426 [Exp1]
« Reply #1 on: May 28, 2018, 08:25:52 PM »
Quote
suddenly a page popped up, with threatening voice and information, telling me that my machine had been attacked and to call some number within 5 minutes.
This is a HTML:FakeAlert ... not in your computer but on the website

This is old news, lots of info/pictures online
https://www.google.no/search?q=html+fakealert&rlz=1C1GGRV_enFR784FR784&source=lnms&tbm=isch&sa=X&ved=0ahUKEwjf16D1gqnbAhWjIpoKHcBTCEIQ_AUICigB&biw=1242&bih=579



Quote
When I ran a second Avast boot scan, it found and quarantined TTF:CVE - 2015 - 2426 [Exp1]
Since this was found doing a boot scan it was most likely a dormant file (not running active)
what was the location of file found ... full file path





CVE - 2015 - 2426  seems to be a old exploit (2015) related to Adobe
If your OS is updated it should not be able to work
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit%3AWin32%2FCVE-2015-2426

https://www.cvedetails.com/cve/CVE-2015-2426/

Patched in 2015
https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2015/ms15-078

« Last Edit: May 28, 2018, 08:37:52 PM by Pondus »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Attacked 28 May 2018 - TTF:CVE - 2015-2426 [Exp1]
« Reply #2 on: May 28, 2018, 08:27:05 PM »
If you want a check, follow instructions here and attach requested logs  >>  https://forum.avast.com/index.php?topic=194892.0