Press release
Lysaker, Norway, 25th October 2007
Norman has set the trojan PDF/Pidief.A to medium risk, and has also set the general threat level to medium. The trojan utilizes vulnerabilities in Adobe Reader and Acrobat to get control over affected systems. Spammed emails are used as spreading mechanism for this attack.
Infected systems are compromised by users running the attached file. The malicious program will use the vulnerabilities in the Adobe programs to shut down Microsoft’s personal firewall and start downloading a trojan from the Internet. The trojan may enable the attacker to take control of the affected system.
Some of the email’s subject lines are:
- INVOICE alacrity
- INVOICE depredate
- STATEMET indigene
The attachment has the following filenames.
- BILL.pdf
- INVOICE.pdf
- YOUR_BILL.pdf
- STATEMET.pdf
This trojan is detected and removed by Norman's release of virus detection files from 24 October 2007 at 17:00 UTC.
Updates from Adobe for these vulnerabilities are available from Adobe’s web site. Norman advices all affected users to install these updates.
Contact and information
www.norman.com
Audun Lødemel, Marketing director, Norman ASA, mobile +47 934 465 31