top | item 41153443

(no title)

Flameancer | 1 year ago

Hmm on iOS I had no issues, but I also don’t have lockdown mode enabled

discuss

order

rogerpeters|1 year ago

I scanned it on VirusTotal, it had never been scanned before, it isn’t picking up detected sig. But, with it’s behaviour analysis it is creeping me out. Take a look at it please… I think you will agree?

That user has been posting a lot of links to pdf’s every day hosted on wordpress platforms and more. I haven’t began scanning those yet.

walterbell|1 year ago

PDF viewed on iOS 17.6 Safari in Lockdown mode, without error.

That's a pre-pub PDF hosted by the Usenix Security 24 conference, which takes place in two weeks. If a respected 30-year old security conference is posting hostile PDFs, that would be newsworthy.

> VirusTotal behavior analysis

What did it say exactly? Just tried a VT scan and it reported a score of 0 out of 95 (green), with zero detailed findings. That was the only/first/last submission of the URL, https://www.virustotal.com/gui/url/f7259d6da00636ec8632741d3...

> That user has been posting a lot of links to pdf’s every day hosted on wordpress platforms and more

Examples, please? I posted the Usenix Security paper. A quick scan of my submissions shows no PDFs in the last two weeks, and one other PDF in the last day, hosted on HP.com.

Flameancer|1 year ago

I’m unfortunately not able to view on desktop since I’m traveling but I’ll have to take a look upon my return tomorrow. Seems fishy the fact it was flagged with lockdown is suspicious.