Malicious PDF — malware analysis report

Static analysis result for SHA-256 6ae2c8f988855df2…

MALICIOUS

PDF

1.1 KB
MD5: c481225ac1b96dca9d3eaa41e67fe1d5 SHA-1: a2eef842fda7e73b57d7086da25c59809a00ed44 SHA-256: 6ae2c8f988855df236be3ef1c76a3bbe41921ac0ab961e15f734cb1dd9644195
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF contains embedded JavaScript that executes app.launchURL to open a URL, which is a common technique for delivering second-stage payloads. The document body mimics a PDF preview error to coerce the user into opening the malicious link. The embedded JavaScript explicitly calls the URL http://securedownload2.duckdns.org:7373/docs/Einreichung211117PDF.zip, which is likely a malicious archive.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Malware.Agent-6384651-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Malware.Agent-6384651-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://securedownload2.duckdns.org:7373/docs/Einreichung211117PDF.zip
    • http://securedownload2.duckdns.org:7373/docs/Einreichung211117PDF.zip',true

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0007_000.js
8b266c8fb1fe83a19ae919f33c5b03178609386455156dd4aa373fea15e74111
pdf-javascript-stream PDF /JS object 7 at offset 0x2F9 92 bytes
javascript_obj0007_001.js
186d55a8c51cd90ac97fee191701cbe4cd801462375865950dee4229ef465a56
pdf-javascript-stream PDF /JS object 7 at offset 0x2F9 90 bytes