Malicious PDF — malware analysis report

Static analysis result for SHA-256 366048d0681d3444…

MALICIOUS

PDF

38.2 KB Created: 2015-08-30 20:30:22 +03:00 Authoring application: 1 (via Softplicity)
MD5: 3ab96f333824a190a06e084142c72a84 SHA-1: 70df350b93b16a87d233715fc58fc191e0b05136 SHA-256: 366048d0681d34446d2ffc3869e4cd444a020affc439c219e9781563450e24cc
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains text and an embedded URL that impersonates a Sears outboard motor manual, likely to trick the user into downloading a malicious file. The ClamAV heuristic confirms this is a Pdf.Dropper.Agent, indicating its purpose is to drop other malware. The embedded URL is the primary indicator for the next stage of the attack.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-8481017-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-8481017-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://my.tomsorg.com/file.php?q=Sears
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00002d9d.bin
72823cd3794ec646740666e29a34283fb2533ed5d1f89562910f14abca9d36a3
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2D9D 19952 bytes
font_01_sfnt_off0000632d.bin
5e8d8a8aa3e6f7d2a41b69855a07a6fffcc3b95eb0bc74364cfa7fe3d68f2961
pdf-font-stream PDF embedded font (sfnt) at offset 0x632D 17200 bytes