Threat behavior
Exploit:JS/Pdfjsc.L is a detection for specially-crafted PDF files that target a software vulnerability in Adobe Acrobat and Adobe Reader. The vulnerability it attempts to exploit is tracked as CVE-2010-0188.
Installation
This exploit commonly arrives in the system when the user visits a webpage that contains a malicious PDF file or opens an email containing the PDF file as an attachment. It contains embedded JavaScript code that can successfully exploit the software vulnerability.
Payload
Downloads arbitrary files
Upon successful exploitation, malicious code executes that attempts to download and execute arbitrary files. In the wild, Exploit:JS/Pdfjsc.L has been observed to contact a server named "fordrebor.cz.cc" to download arbitrary files. At the time of this writing, the files were unavailable for analysis.
Analysis by Marian Radu
Prevention