Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e32f8fb359dfd50…

MALICIOUS

PDF

43.7 KB Created: «xšÏ¦–«S˜œlÉî­Ú‹” Authoring application: ¿ˍÿÑï_‡É0’ÿ̽Ÿ!wèÍv (via ®!ڐôÀïJíÄ/жø†Û¼XÅagýËÞ<»Ã™¼1)
MD5: cfc4e600d12a886beda005a1087d8bed SHA-1: 225c482f31436d8579832249952ee6a618ca03e7 SHA-256: 0e32f8fb359dfd50877a7bbc4972a60dd8d7e4faced65d37116028f8299ea9a2
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF is encrypted, preventing deeper static analysis of its content. However, ClamAV detected it as Pdf.Exploit.Agent-23658, indicating it contains an exploit. The presence of embedded URLs, some of which are not confirmed benign, suggests a potential for malicious redirection or payload delivery. The exploit likely targets a vulnerability to achieve client execution, with spearphishing attachment being the probable initial access vector.

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-23658 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-23658
  • Encrypted PDF (string and stream contents are opaque to static scan) info PDF_ENCRYPTED
    PDF declares /Encrypt — string objects and stream contents are encrypted with the standard security handler (RC4 or AES). On its own this is informational; legitimate encrypted documents include signed contracts, billing statements, and rights-managed material. Static heuristics cannot inspect encrypted payload bytes.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.kitsrus.com
    • http://www.websitetoolbox.com/tool/mb/diykit?forum=13943
    • http://download.microsoft.com/download/vb60pro/install/6/win98me/en-
    • http://www.microchip.com/stellent/idcplg?IdcService=SS_GET_PAGE&nodeId=1407
    • http://www.iec.ch

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
icc_00_off00009c11.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x9C11 3144 bytes