Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b413966e7741ba0…

MALICIOUS

PDF

270.8 KB Created: 2016-04-21 01:53:19 UTC Authoring application: RAD PDF (via RAD PDF 2.36.1.1 - http://www.radpdf.com)
MD5: 05d61c9f327f1674e4765c9f46cdb7f1 SHA-1: cd25c6b241b8a3114a2bce7198999d5b30124144 SHA-256: 1b413966e7741ba00abf24c4628fd42d9eceeb97062603d0147ce26cce3cbd5c
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF containing embedded URLs that point to suspicious domains. The ClamAV heuristic identifies it as a Pdf.Dropper.Agent, indicating it's designed to download and execute further malicious content. The presence of multiple external URIs, including one that appears to be a lure related to Adobe and DHL, strongly suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.0038

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7235406-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7235406-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://maisempresas.co/styles/_viti_doc/_notes/adobe%2016/
    • http://maisempresas.co/styles/_viti_doc/_notes/adobe
    • http://nvnickel.com/cron/chi/DHL_AUTO/index.php?email=%0%
    • http://www.radpdf.com
    • http://www.dynaforms.com
    • http://j646569.myjino.ru/abk
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off000007ec.bin
f3bf9704ae1a1b01d6eaba8c4203245dfddd8957cdd25f52cca46afe823164ba
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7EC 173484 bytes
stream_001_off0001470a.bin
c9ddb44ec7e8b38fdf5b980ecaa8c8dadb424a7c6fa95c5a17b8b9a719879d7b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1470A 169828 bytes