Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ffe8e93c550985d…

MALICIOUS

PDF

291.3 KB Created: 2008-06-11 07:14:06 +02:00 Authoring application: Writer (via OpenOffice.org 2.3)
MD5: ffc5e94bee1926c29e3c4528cd527bee SHA-1: 3a6b172d6f1df19581fb32034e2b3af1bc6a0378 SHA-256: 0ffe8e93c550985d0be5b05e3168de9bc86d5846a8df38461da082623dcc5663
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains embedded URIs that point to external websites, with one heuristic specifically flagging it as a PDF dropper. While no scripts were extracted, the presence of multiple unknown URLs suggests an attempt to redirect the user to potentially malicious sites. The ClamAV detection further supports its malicious nature.

Machine Learning

  • Nyx PDF Classifier clean score 0.0011

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-8011014-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-8011014-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.federalismi.it/
    • http://www.minefi.gouv.fr/
    • http://www.finanze.com/
    • http://www.agenziadelleentrate.net/
    • http://www.agenziefiscali./
    • http://www.agenziaentrate.it/ilwwcm/resources/file/ebcc7747ccf4479/consolidato_istruzioni.pdf
    • http://www.finanze.it/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_035_off00033193.bin
889d6580d16387d1d8990c050d8bf815b3384c4577d6bd6b00fcb7ada1bb3754
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x33193 40044 bytes
font_01_sfnt_off00039ded.bin
2864055f5ffa3aeabddd9aaf05cc7ed59f2e7e48e03257d06af437996e1a0d77
pdf-font-stream PDF embedded font (sfnt) at offset 0x39DED 31528 bytes
font_02_sfnt_off0003f15b.bin
eed69c49abac09d2d6038ca7337de407b80669a3ad180699d2954764943f3114
pdf-font-stream PDF embedded font (sfnt) at offset 0x3F15B 31320 bytes