Home Malware Programs Trojans Exploit.JS.Pdfka.gjc

Exploit.JS.Pdfka.gjc

Posted: March 15, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 89
First Seen: March 15, 2013
Last Seen: August 18, 2020
OS(es) Affected: Windows

Exploit.JS.Pdfka.gjc is a Javascript Trojan that is a part of the malware attacks using PDF exploits. Exploit.JS.Pdfka.gjc attacks Uyghur and Tibetan activists. Exploit.JS.Pdfka.gjc spreads via PDF files, which include the CVE-2013-0640/641 (ItaDuke) exploits. If the exploit, detected as Exploit.JS.Pdfka.gjc, is successful, the PDFs display a clean, 'lure' document to the affected PC user. The first document called '2013-Yilliq Noruz Bayram Merik isige Teklip.pdf' points to a New Year's party invitation. The second one, called 'arp.pdf', is an authorization to request a reimbursement, for a Tibetan activist group. The Javascript exploit code has a large comment block prepended, which was most likely involved to evade detection by certain anti-malware tools. The documents download another malware threat, detected as Trojan.Win32.Agent.hwoo.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



2013-Yilliq Noruz Bayram Merik isige Teklip.pdf File name: 2013-Yilliq Noruz Bayram Merik isige Teklip.pdf
Mime Type: unknown/pdf
Group: Malware file
arp.pdf File name: arp.pdf
Mime Type: unknown/pdf
Group: Malware file
AaAuDA.pdf File name: AaAuDA.pdf
Mime Type: unknown/pdf
Group: Malware file
joint_letter.pdf File name: joint_letter.pdf
Mime Type: unknown/pdf
Group: Malware file
Loading...