Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b1067becf0fe87d…

MALICIOUS

PDF

17.1 KB Created: 2018-10-03 14:27:02 +03:00 Authoring application: dompdf + CPDF
MD5: 01a8374cb39577a6e5aede26c6410e07 SHA-1: c26c7d9c6d997102ddc1fda7c691eec8ccf09372 SHA-256: 5b1067becf0fe87d871abe1902f9e7172d3a9c4fa5b3eecb9c677409b2f2607d
76 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a heuristic indicating it's a password-protected archive lure, suggesting it's designed to trick users into decrypting malicious content. The embedded URL points to a suspicious domain, likely for payload delivery. The document body mimics a bank transaction confirmation to deceive the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9787

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://casellamoving.com/059665EBZWICU/oamo/Personal

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off00000269.bin
30e5ae3b220639ecd208a046e7e5b760754ac1d3809afa27ef473cff59de0b28
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x269 22259 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 16 long base64-like blob(s).