Troj_Pidief.IN Trojan is a specially-crafted .PDF file that exploits a zero-day vulnerability in Acrobat Reader Version 8.x and 9.0.

The said vulnerability causes the application to crash and could potentially allow an attacker to take control of the affected system.

Differing variants of this file drop various malware onto the affected system. Below are some of the malware detected by Trend Micro that are dropped malwares by this PDF:

  • BKDR_NETCL.A
  • EXPL_EXECOD.A
  • JS_SHELLCOD.JS
  • TROJ_AGENT.ZWQA
  • TROJ_FAKEAV.LKQQ

    Technical details can be found at this Trend Micro page.