Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a8a028a86cd9c27…

MALICIOUS

PDF

206.5 KB Created: 2017-11-05 17:12:30 +00:00 Authoring application: Microsoft® Word 2016 (via www.ilovepdf.com) First seen: 2026-05-03
MD5: a4c2141627fbf839fc63c2905527d522 SHA-1: 9d7838770c74463cc5cd0097e428741fec182941 SHA-256: 0a8a028a86cd9c27904cbc1551b250258eb6deea125b489c848290cbb55464b4
124 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link

This PDF document contains a high-confidence heuristic indicating brand-impersonation credential phishing, specifically impersonating Apple. The embedded URL http://go2l.ink/desk091881 is identified as a lure for this phishing attempt. ClamAV also detected the file as Pdf.Dropper.Agent-7226951-0, suggesting it may also function as a dropper for further malicious content.

Machine Learning

  • Nyx PDF Classifier clean score 0.0086

Heuristics 5

  • ClamAV: Pdf.Dropper.Agent-7226951-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7226951-0
  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://go2l.ink/desk091881.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://go2l.ink/desk091881 PDF link annotation
    • http://ocsp.verisign.com0In PDF document text
    • https://i.imgur.com/CuYHT2A.pngIn PDF document text
    • http://www.microsoft.com/typography/ctfontshttp://lucasfonts.comMicrosoftIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In PDF document text
    • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn PDF document text
    • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In PDF document text
    • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In PDF document text
    • http://www.microsoft.com/pkiops/docs/primarycps.htm0@In PDF document text
    • http://www.microsoft.com/Typography/0In PDF document text
    • http://www.monotype.com/html/mtname/ms_symbol.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATIONIn PDF document text
    • http://www.monotype.com/html/type/license.htmlIn PDF document text
    • http://crl.verisign.com/ThawteTimestampingCA.crl0In PDF document text
    • http://crl.verisign.com/tss-ca.crl0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0OIn PDF document text
    • http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00003bcf.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3BCF 372348 bytes
SHA-256: 587d0410d048bb3568812dd8f80786cb54fcc2760faf0b0066a104dce91de133
font_00_sfnt_off00000687.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x687 24332 bytes
SHA-256: ca6c494bb5ef9be7361cfad38425c9e5ec46bc51a29f0a9ed3e0b4866540a7f4