Malicious PDF — malware analysis report

Static analysis result for SHA-256 500c1c14547a77eb…

MALICIOUS

PDF

1.21 MB
MD5: ebce5fb254ae2ff14abe3fd21e102387 SHA-1: 34e5259edcdc8093b612e7ef07298466df52e135 SHA-256: 500c1c14547a77eb106d3e578d58e614002f7af876fd167304bdcf83b29631a8
168 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF contains embedded JavaScript and a hidden ZIP archive with an executable payload, indicating it's designed to exploit vulnerabilities and download further malicious content. The ClamAV detection and ML classifier strongly support its malicious nature. The embedded URL http://192.168.0.1:4444/wipconn is likely a command and control server or download location for the payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • Hidden ZIP payload with executable entries inside PDF stream critical PDF_HIDDEN_ZIP_EXECUTABLE_PAYLOAD
    PDF stream bytes contain an embedded ZIP archive whose local headers name executable payload files. This is not a normal PDF attachment (/EmbeddedFile); it hides Windows payloads inside an ordinary stream, a strong malware-loader or smuggling pattern.
  • ClamAV: Pdf.Exploit.Agent-23692 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-23692
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://192.168.0.1:4444/wipconn
    • http://www.mozilla.org/2004/em-rdf#
    • https://addons.mozilla.org/update/VersionCheck.php?reqVersion=%REQ_VERSION%&id=%ITEM_ID%&version=%ITEM_VERSION%&maxAppVersion=%ITEM_MAXAPPVERSION%&appID=%APP_ID%&appVersion=%APP_VERSION%&appOS=%APP_OS%&appABI=%APP_ABI%
    • https://addons.mozilla.org/extensions/?application=%APPID%
    • https://addons.mozilla.org/themes/?application=%APPID%
    • http://home.netscape.com/NC-rdf#DayFolderIndex
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://home.netscape.com/NC-rdf#

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
hidden_pdf_zip_off000166c5.zip
7be51c4424b7b1461ca3e28b7c42a7976d9b90c9b0b727e1e1a341562c30b2b9
pdf-hidden-zip PDF decompressed stream ZIP payload at offset 0x166C5 1173400 bytes