Trying to reversing the shell code contained within the PDF that seem exploit CVE-2010-4091, in according with the sample reported by MalwareTracker, it’s been founded the following URL: http://212.117.168.89/ad/fi_16.php From Robtex: The URL above at this time is down or not more available. Did really exploited for retrieve malware from
↧