MAAS History
Disclaimer
exocrine exocrine

All information Provided as is.

Entries from September 25, 2011 - October 1, 2011

Sunday
Sep252011

Condition Remains GREEN

RISK is LOW regarding PDF Decoy malicious Apache Installer Reported by F-Secure.

Important Facts

  • It is not a Trojan from a PDF but a Decoy PDF used in conjunction with PostInstall Scripts and Actions from a Package file.
  • The decoy is designed to not raise the suspicion of the user.
  • It installs Apache after the PDF Decoy opens.
  • XProtect has been updated to detect it. 

For more information visit our analysis here.