Malicious PDF — malware analysis report

Static analysis result for SHA-256 5793813d97294d5d…

MALICIOUS

PDF

453.1 KB Created: 2017-10-19 18:34:53 +01:00 Authoring application: Microsoft® Word 2010
MD5: 2e0d28363f08d15c0f78ff4354b8d6c0 SHA-1: 1c788bf5fee6fb0d93ea98e8deba01958b23e5a2 SHA-256: 5793813d97294d5d44a8bb0716cb3f7244a0e6d26a314d9be8357f8bd185d7dc
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file is identified as a malicious PDF by ClamAV. It contains an embedded URI pointing to 'http://exponegocioslitoral.com.br/gf/og.htm'. The document body contains urgency language, suggesting a lure to entice the user to interact with the malicious content. The primary attack pattern involves directing the user to an external URL, which is a common method for phishing or malware distribution.

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7262393-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7262393-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://exponegocioslitoral.com.br/gf/og.htm

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000263e0.bin
ff8d0b8d8d40ebbecbbffe74cdd4fe0bc6027d524087d50faab173955b923185
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x263E0 340444 bytes
stream_005_off00051009.bin
83935880b9974827e91ffea26c43254944ca40b28efd02bace44e6f2fbf997dd
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x51009 276580 bytes