Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a152cf27b31d780…

MALICIOUS

PDF

47.8 KB
MD5: 008e8c42b4e7fc06d00955818e737381 SHA-1: 477f0e569b64e0ea8a55f7d285f2270acc87fb60 SHA-256: 2a152cf27b31d78029faee51bb1a19640cf0a1c8ba0c91af74659c1aace466fe
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The PDF was identified as a lure, presenting an image-based interface to trick users into clicking an external link. The embedded URL, 'https://bit.ly/direcconfirmacion_0', is a URL shortener, commonly used to obscure malicious destinations. The PDF structure also indicates evasion techniques were employed.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5607

Heuristics 4

  • Image-only PDF lure links through URL shortener high PDF_IMAGE_LURE_SHORTENER_LINK
    PDF is image-heavy with little real text and its clickable action points to a URL shortener. This is a high-confidence credential-phishing carrier shape: the visible page is a screenshot-like prompt while the destination is hidden behind redirect infrastructure.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 1 text block(s), carries a click-outward action, and is only 47 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_cff_off00001409.bin
a024f0a8293eb9b99b8d813f011448aa64f25892eb1a5fba78b3eae9b84e663d
pdf-font-stream PDF embedded font (cff) at offset 0x1409 1685 bytes