This Trojan is a specially crafted .PDF file that exploits a known vulnerability in Acrobat Reader 8.1.1 or earlier versions. This vulnerability would cause the application to crash and could potentially allow a malicious user to take control of the affected system.

More information about the said vulnerability can be found on this Web page.

After successfully exploiting the vulnerability, this Trojan then drops and executes a file Trend Micro detects as BKDR_DJD.A. As a result, routines of the dropped backdoor are also exhibited on the affected system.

It also drops a non-malicious .PDF file in the current user's Temporary folder.

Bookmark and Share