Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a8a028a86cd9c27…

MALICIOUS

PDF

206.5 KB Created: 2017-11-05 17:12:30 +00:00 Authoring application: Microsoft® Word 2016 (via www.ilovepdf.com)
MD5: a4c2141627fbf839fc63c2905527d522 SHA-1: 9d7838770c74463cc5cd0097e428741fec182941 SHA-256: 0a8a028a86cd9c27904cbc1551b250258eb6deea125b489c848290cbb55464b4
84 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as a malicious PDF dropper by ClamAV. The document body, though heavily obfuscated, contains indicators of a callback phishing lure, prompting the user to contact a phone number for a fabricated issue. An external URI was also extracted, likely part of the lure or payload delivery.

Machine Learning

  • Nyx PDF Classifier clean score 0.0086

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7226951-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7226951-0
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://go2l.ink/desk091881
    • http://ocsp.verisign.com0
    • https://i.imgur.com/CuYHT2A.png
    • http://www.microsoft.com/typography/ctfontshttp://lucasfonts.comMicrosoft
    • http://en.wikipedia.org/wiki/MIT_License
    • http://www.microsoft.com/typography/fonts/default.aspx
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
    • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
    • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
    • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
    • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��
    • http://www.microsoft.com/pkiops/docs/primarycps.htm0@
    • http://www.microsoft.com/Typography/0
    • http://www.monotype.com/html/mtname/ms_symbol.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATION
    • http://www.monotype.com/html/type/license.html
    • http://crl.verisign.com/ThawteTimestampingCA.crl0
    • http://crl.verisign.com/tss-ca.crl0
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0O
    • http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0
    • http://www.microsoft.com/typography

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00003bcf.bin
587d0410d048bb3568812dd8f80786cb54fcc2760faf0b0066a104dce91de133
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3BCF 372348 bytes
font_00_sfnt_off00000687.bin
ca6c494bb5ef9be7361cfad38425c9e5ec46bc51a29f0a9ed3e0b4866540a7f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x687 24332 bytes