Pdf.Dropper.Agent-7596619-0 — PDF malware analysis

Static analysis result for SHA-256 442fa381ed910255…

MALICIOUS

PDF

25.6 KB Created: 2003-04-18 00:24:35 Authoring application: 商品房买卖合同.doc - Microsoft Word (via Acrobat PDFWriter 5.0 for Windows NT)
MD5: 83daece9c36c0b9a5c1e9f7fc7771f72 SHA-1: 28f650ac5b611d21db48ec171d95216c4e445142 SHA-256: 442fa381ed910255fb529bea51dad87c2048e673e23a492b1568b695eb92c1a0
100 Risk Score

Malware Insights

Pdf.Dropper.Agent-7596619-0 · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a hidden external HTML iframe, a common technique for redirecting users to malicious sites. ClamAV identified this file as Pdf.Dropper.Agent-7596619-0. The embedded URL, http://127.0.0.1/m.htm, is likely used to host or serve a secondary malicious payload.

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7596619-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7596619-0
  • PDF contains hidden external HTML iframe high PDF_HIDDEN_HTML_IFRAME
    PDF bytes contain a hidden zero-size HTML iframe pointing to an external HTTP(S) URL. This is a strong malicious dropper/redirect indicator and is not expected in ordinary PDF content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://127.0.0.1/m.htm