Malicious PDF — malware analysis report

Static analysis result for SHA-256 4dbcf562ce7345c4…

MALICIOUS

PDF

313.1 KB Created: 2010-09-17 21:28:19 Authoring application: Joomla! 1.5 - Open Source Content Management (via TCPDF 2.5.000_PHP4 (http://www.tcpdf.org))
MD5: 8596d5dc2fb797cd0f7afb8f8034e05e SHA-1: 63abce7b0f2d4dab71da9decafbf05d999993c08 SHA-256: 4dbcf562ce7345c4d927d801624ef2ea3450018dfab1ffe6a3ff4871d4352d2b
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a hidden HTML iframe, a common technique for embedding malicious content or redirecting users to malicious sites. ClamAV detected this file as Html.Spyware.IMG-7, indicating a known spyware component. The embedded URL points to an unknown resource, which is highly suspicious in this context. The PDF structure itself does not contain readable content, suggesting its primary purpose is to exploit vulnerabilities or act as a container for malicious code.

Heuristics 3

  • ClamAV: Html.Spyware.IMG-7 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Html.Spyware.IMG-7
  • PDF contains hidden external HTML iframe high PDF_HIDDEN_HTML_IFRAME
    PDF bytes contain a hidden zero-size HTML iframe pointing to an external HTTP(S) URL. This is a strong malicious dropper/redirect indicator and is not expected in ordinary PDF content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.codeforum.cn/free/max1.htm
    • http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/exif/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://www.iec.ch

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000b76c.bin
a5337ef1f5a0dfe4dc8fa6b4f3ef847a53624800b5928a0eeef5b888ceecaabc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xB76C 264072 bytes