Malicious PDF — malware analysis report

Static analysis result for SHA-256 1bd5117cd7c17325…

MALICIOUS

PDF

41.8 KB
MD5: 64b88d474f847ee7adbd25645ad50373 SHA-1: 1095dcca2676cff0656e24ab90af938496206a63 SHA-256: 1bd5117cd7c1732508daa6954ef408d4a5b6c5761bebfe276e5fca930ccd5669
120 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The file is detected as Win.Exploit.Jailbreak-1 by ClamAV, indicating it's an exploit. The embedded URLs, particularly http://jailbreakme.com/wad.bin, suggest a download and execution attempt. The document body contains text related to downloading and jailbreaking, further supporting the exploit and payload delivery hypothesis. The presence of these elements strongly suggests an attack pattern focused on exploiting a vulnerability to compromise the user's system.

Heuristics 3

  • ClamAV: Win.Exploit.Jailbreak-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Exploit.Jailbreak-1
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://jailbreakme.com/wad.bin
    • http://jailbreakme.com/wad.binOops...QuitRetryFile
    • http://www.apple.com/DTDs/PropertyList-1.0.dtd

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_cff_off00000442.bin
373244e51680320940dbce66af6c96883781e879514513057fc4f1d0a7bf54e7
pdf-font-stream PDF embedded font (cff) at offset 0x442 40357 bytes
Detection
ClamAV: Win.Exploit.Jailbreak-1
Obfuscation or payload: unlikely