Sunday
Sep252011
Condition Remains GREEN

RISK is LOW regarding PDF Decoy malicious Apache Installer Reported by F-Secure.
Important Facts
- It is not a Trojan from a PDF but a Decoy PDF used in conjunction with PostInstall Scripts and Actions from a Package file.
- The decoy is designed to not raise the suspicion of the user.
- It installs Apache after the PDF Decoy opens.
- XProtect has been updated to detect it.
For more information visit our analysis here.

tagged
Condition:GREEN
