Skip to main content

Trojan-Dropper:JS/PdfDropper

Classification

Category:

Malware

Type:

Trojan-dropper

Aliases:

  • Trojan-dropper:JS/PdfDropper.A

Summary

Trojan-dropper:JS/PdfDropper identifies specially-crafted PDF files that drop and execute a document file. The dropped document file in turn contains code that downloads and runs additional harmful programs.

Removal

Technical Details

The PdfDropper file is usually distributed in spam email campaigns. Its appearance and content is usually designed to lure unsuspecting users into opening the file. The PDF file is specially crafted to contain and deliver a document file, which in turn has malicious macro code embedded in it.

Opening the PDF file causes JavaScript code included in it to run, which drops and opens the document file. This executes the embedded macro code, which contacts a remote server to download and run other harmful programs on the machine.

In previously analyzed samples, the downloaded programs include ransomware (Locky) and banking trojans (Dridex).

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.