Malicious PDF — malware analysis report

Static analysis result for SHA-256 4d9551511e335cf1…

MALICIOUS

PDF

85.1 KB Created: 2016-03-13 22:18:06 +06:00 Authoring application: wkhtmltopdf 0.12.3.2 (via Qt 4.8.7)
MD5: cf12a1496a48293f445ae67528112cef SHA-1: 3982d638348dab90869a34a29a4f06b96292c65b SHA-256: 4d9551511e335cf1e4fba62166fb0221e3f31d5b3d4b7d74b46c504d4303231e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded URLs that redirect to a download page, likely serving a malicious payload. The ClamAV heuristic 'Pdf.Dropper.Agent-7573354-0' strongly indicates its dropper functionality. The document body, though truncated, suggests a lure related to software activation codes, further supporting the malicious intent.

Machine Learning

  • Nyx PDF Classifier clean score 0.0029

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7573354-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7573354-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mymediasearchnowthree.com/3489/download.php?id=3489&name=how+to+generate+autocad+2010+activation+code+bit+crack&sid=wppdf16
    • http://yournetmediastoreone.com/3489/download.php?id=3489&name=how+to+generate+autocad+2010+activation+code+bit+crack&sid=wppdf16

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00001412.bin
a8c375e3ffbf277addaa7019ed67b51d76cca18dcdd810b05d443b31dd437546
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1412 548226 bytes
font_00_sfnt_off00011ed2.bin
26acc9c4f9ecf9de3e481a442b28f915c7efad39a034141301a0447737e59e98
pdf-font-stream PDF embedded font (sfnt) at offset 0x11ED2 22372 bytes