Malicious PDF — malware analysis report

Static analysis result for SHA-256 35754949a092fca9…

MALICIOUS

PDF

198.7 KB Created: 2017-11-14 13:34:27 -05:00 Authoring application: Microsoft® Word 2016 (via Neevia Document Converter Pro v6.9 (http://neevia.com))
MD5: a93742b523e74f11e409617e755103a6 SHA-1: a321ebc77920c74c0b90b7776cdd528383c07bfa SHA-256: 35754949a092fca95e3f87289fff7f79ff9409ff97eb2eea16fa4561a5baae4f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was detected as malicious by ClamAV with the signature Pdf.Dropper.Agent-7248197-0. Static analysis revealed an embedded external URI pointing to https://pluorgmond.org/office, which is likely the next stage of the attack. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5520

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7248197-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7248197-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pluorgmond.org/office
    • http://neevia.com\))/CreationDate(D:20171114133427-05
    • http://neevia.com
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00007082.bin
807c175c2b4e16f8ef38d13f67dbf4e98fa6f389f6b8108255afde3240b9f7c3
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7082 190852 bytes
stream_002_off0001d073.bin
a5df9f667ba914cabf5d639390bb086332e56f7381fa8022c100534d3b9f7f76
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1D073 174876 bytes