Malicious PDF — malware analysis report

Static analysis result for SHA-256 630465ac29f9aee3…

MALICIOUS

PDF

9.2 KB Created: 2009-02-19 14:45:49 -02:00 Authoring application: Writer (via OpenOffice.org 3.0)
MD5: f7576b9718577147e2c76b23740eec4d SHA-1: f2a4e592d0c3fb45603e22e97000949bfde5aa45 SHA-256: 630465ac29f9aee3be068f6c2df834745298d6bff0baa79b9556c3fdf1a6f2d2
132 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains a launch action that directs to an external URL, indicating an attempt to execute code or download a payload. ClamAV detection and ML classification confirm its malicious nature. The embedded URL is the primary indicator of a potential secondary stage download.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9781

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-35541 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-35541
  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://test1.ru/copy/load.phpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA