Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e36bf6ed8b336b5…

MALICIOUS

PDF

316.5 KB Created: 2023-04-20 16:48:32 -07:00 Authoring application: iTextSharp’ 5.5.13.2 ©2000-2020 iText Group NV (AGPL-version)
MD5: e57de347f22ff46f8546575d9e71fef1 SHA-1: bdf9e160230493a3d972ff72f1550f206e39a722 SHA-256: 5e36bf6ed8b336b5700f8c76effa2576b0ea7743f41b021178a6b9fc7a2885fb
72 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file was flagged as malicious by an ML classifier and contains a clickable URI pointing to a raw IP address. The document body is heavily obfuscated and contains no readable text, suggesting it is designed to be an image-based lure. The presence of a raw IP address in a URI is a strong indicator of malicious intent, likely to download a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9109

Heuristics 3

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • PDF paints image(s) but contains no text operators medium PDF_IMAGE_ONLY_LURE
    PDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://79.132.130.147/main.php