Malicious PDF — malware analysis report

Static analysis result for SHA-256 3bdf4f8afa9dfdba…

MALICIOUS

PDF

405.0 KB
MD5: 410eaca2428a212fd30f899216b8c810 SHA-1: 408d3986d86baf222e6b5adf15cdc7fe102cfeb6 SHA-256: 3bdf4f8afa9dfdba97e70ad3fe3f4160a376a2a91fe36b48621ec3d6afaf32e5
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was identified as malicious by ClamAV with the signature Pdf.Dropper.Agent-7251534-0. A critical heuristic firing indicated an external URI, http://adobe-net-reader.netne.net/phpnet.php?code=2000500, was embedded within the decompressed stream. This suggests the PDF is designed to redirect users to a potentially harmful website, likely for credential harvesting or malware delivery.

Machine Learning

  • Nyx PDF Classifier clean score 0.0009

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7251534-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7251534-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_096_off00064c6c.js
bf96c540a6bff0492df76c1627d4d3e26efe10ff53109e686257df6f4341e571
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x64C6C 1872 bytes