Sunday
Sep252011
Condition Remains GREEN
Sunday, September 25, 2011 at 06:20PM
RISK is LOW regarding PDF Decoy malicious Apache Installer Reported by F-Secure.
Important Facts
- It is not a Trojan from a PDF but a Decoy PDF used in conjunction with PostInstall Scripts and Actions from a Package file.
- The decoy is designed to not raise the suspicion of the user.
- It installs Apache after the PDF Decoy opens.
- XProtect has been updated to detect it.
For more information visit our analysis here.
Sean OConnell Public | Comments Off |
tagged Condition:GREEN