Troj/PDFEx-GD

Category: Viruses and Spyware Protection available since:30 Apr 2012 06:03:16 (GMT)
Type: Trojan Last Updated:16 Oct 2013 08:48:02 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/PDFEx-GD include:

Example 1

File Information

Size
14K
SHA-1
1da150c71489e28d9f7b0826391f09bc6be5af64
MD5
50a0efdaa7957d5da5abcf705b8aff26
CRC-32
cba10f31
File type
Adobe Portable Document Format (PDF)
First seen
2012-09-27

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\AcrA8A0.tmp
Processes Created
  • c:\program files\adobe\reader 8.0\reader\acrord32.exe
HTTP Requests
  • http://cateme.info/NcfgBn
DNS Requests
  • cateme.info

Example 2

File Information

Size
13K
SHA-1
3936b1695fae50740c575eb4ab5af46b00679a24
MD5
bce58804e571162f30b9ef34f4471c1b
CRC-32
44fb56d9
File type
Adobe Portable Document Format (PDF)
First seen
2012-01-24

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\Acr8E90.tmp
Processes Created
  • c:\program files\adobe\reader 8.0\reader\acrord32.exe
HTTP Requests
  • http://asewashere.info/w.php
DNS Requests
  • asewashere.info

Example 3

File Information

Size
8.9K
SHA-1
7921b4b1445e14b6557207589d9137c136ed297d
MD5
d105debd55dca0edf4d6bf5490d156d7
CRC-32
92d48990
File type
Adobe Portable Document Format (PDF)
First seen
2012-08-10

Other vendor detection

Kaspersky
HEUR:Exploit.Script.Generic

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\AcrA6CB.tmp
Processes Created
  • c:\program files\adobe\reader 8.0\reader\acrord32.exe
DNS Requests
  • chaffeurjobs.info

download Try Sophos products for free
Download now