Malware Information

Malware nameExploit.PDF.3355
TypeExploit
Affected platformWin32
Media-Typeapplication/pdf
MD5 checksumAF19E1CB7E54DFC2A3E8CCE0DD048FCC
Static fileno
Filesize5,264 Bytes
Alias names
(also known as)
SophosTroj/PDFJs-G
McAfeeExploit-PDF.f
Protection
Webwasher Anti Malware7001.44.x
Side effects
  • Downloads a malicious file
  • Makes use of software vulnerability
PropagationNo own spreading routine

Description:

Files

It tries to download a file:

– The location is the following:
• http://www.gamunkl.com/fifa/**********
It is saved on the local hard drive under: %SYSDIR%\%random character string%.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too.