Home Malware Programs Trojans Troj/PDFJS-ADE

Troj/PDFJS-ADE

Posted: March 20, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 110
First Seen: March 20, 2013
Last Seen: June 16, 2022
OS(es) Affected: Windows

Troj/PDFJS-ADE is a Trojan downloader that connects to an external server for downloading and installing malicious software automatically. Attacks linked to Troj/PDFJS-ADE are prominently associated with misleading e-mails that use fake news articles with European themes (such as the Cyprus bank bailout or the papal election) to encourage victims to click on their malicious links. These links redirect you to a Blackhole Exploit Kit, which launches attacks a variety of potential system vulnerabilities through components like Troj/PDFJS-ADE. Besides the standard defenses against BEK-based attacks, SpywareRemove.com malware experts suggest that you refuse to follow links like the ones noted above unless you absolutely trust the source, and navigate to trustworthy sites by typing the appropriate web address.

When a Fake 'CNN' Delivers Trojans to Your Mailbox

Troj/PDFJS-ADE is part of an ongoing campaign of spam e-mail attacks that borrow the graphical design of a CNN news notification to lend an air of legitimacy to their messages. So far, these e-mail messages have limited themselves to popular news events from Europe, with the latest templates discussing the controversial bailout plan for Cyprus. However, the news that supposedly is being offered up on a hot plate actually contains more than a trace of poison, with the enclosed links redirecting victims to websites hosting the Blackhole Exploit Kit.

The Blackhole Exploit Kit, or BEK, scans your PC for appropriate software versions that can be attacked through various vulnerabilities, including both outdated ones and zero-day ones (the latter of which, SpywareRemove.com malware experts emphasize, cannot be blocked by installing security patches). Troj/PDFJS-ADE is one of the primary components that BEK uses, with the ultimate result being the installation of malicious software onto your PC. Troj/PDFJS-ADE requires both Adobe software and JavaScript vulnerabilities to pull its attack off, whereas one of its counterparts, Troj/SwfExp-BN, can make do with Flash.

There aren't any symptoms of this attack, so if you've clicked on a link that resembles the above description, SpywareRemove.com malware experts advise you to assume your computer is infected.

Why Being Up-To-Date Means a Big Boost in Safety from Troj/PDFJS-ADE

As noted earlier in this article, Troj/PDFJS-ADE and Blacole both require appropriate software vulnerabilities before they can install malware onto your PC. For this reason, SpywareRemove.com malware researchers stress the proper installation of security patches as soon as they're available, which can drastically lower the amount of vulnerabilities that can be utilized for such drive-by-download assaults. Nonetheless, patching all of your software never should be considered a perfect form of defense against these attacks, and you never should trust links from unusual e-mails or other sources of notable suspicion.

If your PC has been exposed to web content associated with Troj/PDFJS-ADE's attacks, anti-malware software generally should be employed immediately. Payloads linked to Blackhole Exploit Kits may exhibit obvious symptoms (such as the fake alerts of a Police Ransomware Trojan) or zero symptoms (in the case of a banking Trojan or other types of spyware), and deleting Troj/PDFJS-ADE or Troj/PDFJS-ADE's payload by yourself is inadvisable unless, of course, you're a professional in PC security.

Technical Details

Additional Information

The following messages's were detected:
# Message
1BBC-Email: Bank of America happy of Cyprus Central Bank Warns of Capital Flight
2BBC-Email: Cyprus 'Bank Raid' by Euro Banks
3BBC-Email: Cyprus Bank-Levy Passage in Doubt as EU Shows Aggression
4BBC-Email: Cyprus already confirmed one time tax withdrawal TODAY!
5BBC-Email: Cyprus banks shut extended to Monday
6BBC-Email: Cyprus can amend bailout terms
7BBC-Email: Cyprus decided to rise bank tax up to 15% for Corporate sector
8BBC-Email: Cyprus effect on stocks likely long-term
9BBC-Email: Cyprus government today accepted one time bank tax withdrawal but higher than expected
10BBC-Email: Cyprus races to rework savings tax after closing banks till Thursday
11BBC-Email: Cyprus rises tax value and confirmed one time withdrawal!
12BBC-Email: EU wants rise of Cyprus bank levy
13BBC-Email: Several countries' deposits may be excluded from Cyprus Bank Tax, Why? We got a draft.
14BBC-Email: The Cyprus eurozone bailout conditions are bank robbery, 15%!!!
15BBC-Email: US banks hurt by Cyprus news
16BBC-Email: USA government decided to follow Cyprus and rise deposit taxes!!!

Loading...