Welcome to the Virus Encyclopedia of Panda Security.
It downloads samples of malware to the affected computer. It reaches the computer in a file with PDF format, which exploits a vulnerability present in certain versions of Acrobat Reader. This file can reach the computer via email.
|First detected on:||Oct. 29, 2007|
|Detection updated on:||Nov. 16, 2007|
|Yes, using TruPrevent Technologies
EbodaR.A is a Trojan that downloads different samples of malware to the affected computer.
It reaches the computer in a file with PDF format, which exploits a vulnerability present in certain versions of Acrobat Reader. It is concretely the CVE-2007-5020 vulnerability.
When the PDF document is run, it disables the Windows XP firewall and then EbodaR.A is downloaded and run.
EbodaR.A is easy to recognize, as it reaches the computer in a file with PDF format. This file usually reaches the computer in an email message, though it is not the only means of infection.
The email messages in which it arrives can have the following features:
- Subject: any of the following, among others:
- The attached file can have any of the following names, among others: