Malicious PDF — malware analysis report

Static analysis result for SHA-256 094f67fc476dfdee…

MALICIOUS

PDF

29.2 KB Authoring application: LibreOffice Draw
MD5: 6f7adb4cf54d22c3feb0c74e134b19f3 SHA-1: a1fda977147d4560b2111ea48f46f243ee0727b1 SHA-256: 094f67fc476dfdeeaf776b760e075a09d3a145ced2999d6cb6b23c300a44ccd7
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by multiple heuristics, including a critical ClamAV detection and an ML classifier. It contains embedded URLs that likely lead to the download of further malicious content, such as the PDF 'zesav.pdf'. The presence of these URLs suggests an attempt to trick the user into downloading and executing a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7805885-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7805885-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://canadianholisticcenter.com/uploads/1/3/0/2/130272512/zesav.pdf
    • http://northshorepaintinginc.com/uploads/1/3/0/5/130540176/5671722.pdf
    • http://juxaziraz.shopping-chao.com/uploads/2020/01/29/vomabubelip_zetuson_zupigirodedo_nesasewurosezi.pdf
    • http://daddio.io/uploads/1/3/0/3/130313063/wadegefuximavad-fufakitilowis-revizuparuxonin-tefufap.pdf
    • http://adoptme.info/uploads/1/3/0/3/130323465/130323465.html#lonely+planet+guide+book+new+zealand

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010aa.bin
544fcd0dcf66007083315d31cd1558cc56caecfe0fbc5a0ec7d4b756e6540f20
pdf-font-stream PDF embedded font (sfnt) at offset 0x10AA 8484 bytes