Mal/ASFDldr-A detects malicious media files with the .asf (Advanced Streaming Format) extension.
The malicious files use Microsoft Media Player's scripting capability to open a web browser to an infected site instead of playing the video the user was hoping for.
Microsoft has issued an update for this vulnerability:
http://support.microsoft.com/kb/828026
Most of the files detected as Mal/ASFDldr-A do not contain any video or audio content. They are several megabytes in size due to null padding.
Mal/ASFDldr-A tries to pass itself off as media coming from artists such as:
Lady Gaga
ABBA
Taio Cruz
Madoona (sic)
Examples of Mal/ASFDldr-A include:
Example 1
File Information
- Size
- 3.3M
- SHA-1
- 00dae3cf8cfe83108922efad0bc4e7963a8abd25
- MD5
- 386e554040706f3dd0d7e831e3839b62
- CRC-32
- 13667dc8
- File type
- video/x-ms-asf
- First seen
- 2010-10-05
Example 2
File Information
- Size
- 3.6M
- SHA-1
- 00ea34a19ecd0571233c6475fcee2af564c3fb75
- MD5
- 02356173e3ebfb4431e62f61b0452f62
- CRC-32
- f7f0d771
- File type
- video/x-ms-asf
- First seen
- 2010-11-07
Example 3
File Information
- Size
- 3.3M
- SHA-1
- 01311441bf8112add337a1448c59c698c941c2b6
- MD5
- 3f206a2373ae5e987939ac7a38885ed3
- CRC-32
- 9ba5a4fe
- File type
- video/x-ms-asf
- First seen
- 2011-01-29