Malicious PDF — malware analysis report

Static analysis result for SHA-256 279b5c7d155db268…

MALICIOUS

PDF

289.2 KB Created: 2017-05-17 16:33:53 +02:00 Authoring application: RAD PDF (via RAD PDF 2.38.3.1 - http://www.radpdf.com)
MD5: 4b1328f63a301ee73b4a46504717ae3f SHA-1: 01d2f97b5cf6cf58af9b938c314ca424d4cfaca6 SHA-256: 279b5c7d155db268b644dd2514c0c7df5ba70219b664807e8068b62241e6b305
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains multiple embedded URLs that mimic DHL Express delivery notifications, suggesting a phishing or malware distribution attempt. The ClamAV detection 'Pdf.Dropper.Agent-7241514-0' further supports its malicious nature. The embedded URLs are likely intended to redirect the user to a malicious site to download further payloads or steal credentials.

Machine Learning

  • Nyx PDF Classifier clean score 0.0651

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7241514-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7241514-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netstatng.com/DHL_Express/DHL/Exp/index.html
    • https://aibengroup.com/DHL_Express-/DHL/Exp/index.html
    • http://crown.org.bd/DHL_Express/DHL/Exp/index.html
    • http://lauraelkaslassy.com/DHL_Express/DHL/Exp/index.html
    • http://www.radpdf.com)/Creator(RAD
    • http://www.dynaforms.com
    • http://www.radpdf.com
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00000f1f.bin
f3bf9704ae1a1b01d6eaba8c4203245dfddd8957cdd25f52cca46afe823164ba
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF1F 173484 bytes