Yesterday, Xavier wrote a diary entry about malicious UDF files.
I wrote about the analysis of .ISO files before, and it turns out the same techniques work for UDF files too.
Python module isoparser can also parse UDF files:
We can retrieve the content:
And calculate the hash of the contained EXE:
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.