|From: PDF@Exploit| |To: Zeus@Trojan| |Subject: Steals Bank Credentials|

Written by traversecode on . Posted in Bot Analysis, Exploit Analysis, Malware Analysis

INTRODUCTION: I guess the Title would say what this post will contain. This post explains how an Exploit code embedded in PDF uses a Vulnerability and installs a Zeus Trojan in a victims machine and what banks the Trojan targets to steal user credential. THE FLOW: In the above Diagram, the user is either Social Engineered or visits malicious website and happen to view a malicious PDF doc which contains the exploit code. Based on the version of Adobe Reader used by the user,