Malicious PDF — malware analysis report

Static analysis result for SHA-256 279b5c7d155db268…

MALICIOUS

PDF

289.2 KB Created: 2017-05-17 16:33:53 +02:00 Authoring application: RAD PDF (via RAD PDF 2.38.3.1 - http://www.radpdf.com) First seen: 2026-05-04
MD5: 4b1328f63a301ee73b4a46504717ae3f SHA-1: 01d2f97b5cf6cf58af9b938c314ca424d4cfaca6 SHA-256: 279b5c7d155db268b644dd2514c0c7df5ba70219b664807e8068b62241e6b305
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document identified as malicious by ClamAV (Pdf.Dropper.Agent-7241514-0). It contains multiple embedded URLs, with the primary one being https://netstatng.com/DHL_Express/DHL/Exp/index.html, suggesting a phishing lure related to DHL Express. Although no scripts were explicitly extracted, the PDF structure and embedded URIs indicate it's designed to redirect users to potentially malicious content, likely for further exploitation.

Machine Learning

  • Nyx PDF Classifier clean score 0.0651

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7241514-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7241514-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netstatng.com/DHL_Express/DHL/Exp/index.html PDF link annotation
    • https://aibengroup.com/DHL_Express-/DHL/Exp/index.htmlIn PDF document text
    • http://crown.org.bd/DHL_Express/DHL/Exp/index.htmlIn PDF document text
    • http://lauraelkaslassy.com/DHL_Express/DHL/Exp/index.htmlIn PDF document text
    • http://www.radpdf.comIn PDF document text
    • http://www.radpdf.com)/Creator(RADIn PDF document text
    • http://www.dynaforms.comIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYouIn PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0ZIn PDF document text
    • http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn PDF document text
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In PDF document text
    • http://www.microsoft.com/Typography/0In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00000f1f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF1F 173484 bytes
SHA-256: f3bf9704ae1a1b01d6eaba8c4203245dfddd8957cdd25f52cca46afe823164ba