| Malware name | Exploit.PDF.3355 | | Type | Exploit | | Affected platform | Win32 | | Media-Type | application/pdf | | MD5 checksum | AF19E1CB7E54DFC2A3E8CCE0DD048FCC | | Static file | no | | Filesize | 5,264 Bytes | Alias names (also known as) | | Sophos | Troj/PDFJs-G | | McAfee | Exploit-PDF.f |
| | Protection | | Webwasher Anti Malware | 7001.44.x |
| | Side effects | - Downloads a malicious file
- Makes use of software vulnerability
| | Propagation | No own spreading routine |
|
Description:
Files
It tries to download a file:
– The location is the following:
• http://www.gamunkl.com/fifa/**********
It is saved on the local hard drive under: %SYSDIR%\
%random character string%.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too.