Malicious PDF — malware analysis report

Static analysis result for SHA-256 67c4691c1d99f52e…

MALICIOUS

PDF

60.5 KB
MD5: 785cc2dca96525c74dc9fbe8d8474ce5 SHA-1: 9cb6c5bf9c703cd22d9052a0bea4d8b7da768047 SHA-256: 67c4691c1d99f52e392edd443d6f11d7c20a25651727b379b3649aaa83faae0e
84 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file is identified as a malicious phishing lure due to its structure and embedded link. The heuristic 'PDF_IMAGE_LURE' indicates it uses an image to trick users, and 'PDF_DIRECT_PAYLOAD_LINK' confirms a direct link to an executable payload. The primary IOC is the URL that serves the malicious executable.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.2627

Heuristics 4

  • PDF link points directly to executable/archive payload critical PDF_DIRECT_PAYLOAD_LINK
    PDF contains a clickable HTTP(S) URI whose path ends in an executable, script, shortcut, disk image, or archive extension. Documents can legitimately link to installers, so this is a high-risk delivery indicator rather than a standalone exploit fingerprint.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 2 text block(s), carries a click-outward action, and is only 60 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.nevrona.com/rave
    • https://247info.click/doc.exe
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/