Malicious PDF — malware analysis report

Static analysis result for SHA-256 5970c95abe0bbb48…

MALICIOUS

PDF

383.3 KB Created: 2007-05-07 21:10:25 -05:00 Authoring application: PScript5.dll Version 5.2.2 (via Acrobat Distiller 6.0 (Windows))
MD5: d751944e63e30bc6a83c1eeaf806cab4 SHA-1: 89309e4e7bfd107467703b41d09cb7b3c0bf52eb SHA-256: 5970c95abe0bbb48d1522a41a5609654e07ec98ec6e6ef33eda5d5ad74c1ae39
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The ClamAV heuristic 'Pdf.Dropper.Agent-7596667-0' indicates this PDF is designed to drop or redirect to malicious content. The presence of embedded URLs, specifically 'http://www.goldwindos2000.com/xiaoaone/index.htm' and 'http://www.goldwindos2000.com/hkeraone/hker.htm', suggests a phishing or redirection attempt. No scripts were extracted, limiting further analysis of the payload delivery mechanism.

Machine Learning

  • Nyx PDF Classifier clean score 0.0086

Heuristics 2

  • ClamAV: Pdf.Dropper.Agent-7596667-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7596667-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.goldwindos2000.com/xiaoaone/index.htm
    • http://www.goldwindos2000.com/hkeraone/hker.htm
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/exif/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/xap/1.0/rights/
    • http://purl.org/dc/elements/1.1/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
icc_00_off00005bfd.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x5BFD 3144 bytes
font_00_cff_off0001080c.bin
d1dbee7701118da63e78ffe4cd4c7ea27688e2f998ce91c434821c9a0190d171
pdf-font-stream PDF embedded font (cff) at offset 0x1080C 1337 bytes