Threat behavior
Exploit:Win32/Pdfjsc.EP is a detection for specially-crafted PDF files that attempt to exploit a software vulnerability in Adobe Acrobat and Adobe Reader.
These PDF files contain an embedded JavaScript that, when loaded (as when the files are opened in a vulnerable version of Adobe Acrobat or Adobe Reader), executes a shellcode that exploits the vulnerability. The shellcode may perform any action, such as downloading and running other malware.
The vulnerability Exploit:Win32/Pdfjsc.EP attempts to exploit is CVE-2009-4324.
Exploit:Win32/Pdfjsc.EP usually arrives in the computer when the user visits a Web page that contains a malicious PDF file or opens an e-mail message containing the PDF file as an attachment.
In the wild, files detected as Exploit:Win32/Pdfjsc.EP have been observed to contact one of the following domains to download additional malicious files:
193.104.253.51
193.104.253.52
306concepts.com
349832409002394.com
36concepts.com
38jiajaoly.com
5cm-gggg.org
66.197.237.165
77.221.153.178
842389423478923.com
91.201.28.58
91.201.28.66
92.63.97.105
94.75.236.65
95.211.101.124
95.211.24.117
95.211.99.121
aaa.fozdegen.com
bannnas.com
bbb.fozdegen.com
besbab.com
bindtool.com
boluoniu.su
brandplo.com
chided.in
click-explorer.ir
clipplaces.com
cogs.trfafsegh.com
datingconv.com
defashizmu.net
denurtured.info
dersu2.com
domafon.info
dsfdsf.com
eee.fozdegen.com
fallenhome.in
fe1kfraud.com
fozdegen.com
gomoneygo.info
grinchalina2.com
hassled.info
hulinadobaranublja.com
i-k-l-m-n.org
inclabtec.biz
indiospiritss.com
investordoctors.com
jojo.salefale.com
kink-report.com
klgs.trfafsegh.com
listsell.biz
lll.sobakozgav.net
lusia777.com
main2strn.com
mastornet.com
nauseateyed.info
neon-cardaras.com
notydivi.com.tw
pentoosz.com
poimejy.info
polubomucom.com
poperlock.com
royalnah.com
secureherb.com
sentenced121.info
serverbestint.com
sobakozgav.net
spain.salefale.com
spicexpert.com
stibbso.com
stx7.net
test1.salefale.com
test2.salefale.com
trfafsegh.com
trfn.salefale.com
vafljam.net
vibro-stream.org
wellkoon.com
wftguy.com
whereisthestar.com
wqdfr.salefale.com
www.gaddem.info
zxfr.salefale.com
Analysis by Marian Radu
Prevention