Malicious PDF — malware analysis report

Static analysis result for SHA-256 749234f37f41399a…

MALICIOUS

PDF

20.8 KB Created: A9÷pB¢#ʋ¹"R`w"â- Authoring application: Íf¥+S6Õwv–Üü)Wv`2´e'=õ+ß¾ (via Íf¥+SàN~‘Õë{Bm~"ò"tÌ Â­œè)
MD5: 61a6678153749da486d7d2baafeeca5c SHA-1: 4d98dad3db935913b0a622d52ec0abfcd30b49a7 SHA-256: 749234f37f41399a487ab23a4a0d2cffeb89a15ebf2b66d2d636ab94166aea5a
112 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF is encrypted and contains an OpenAction, indicating an attempt to hide malicious content. It also embeds a hidden external HTML iframe, likely directing the user to a malicious URL. The ML classifier strongly suggests maliciousness. The embedded URL and the URL found in the document body, www.build365.com, are suspicious and likely serve as the payload delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9275

Heuristics 3

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • PDF contains hidden external HTML iframe high PDF_HIDDEN_HTML_IFRAME
    PDF bytes contain a hidden zero-size HTML iframe pointing to an external HTTP(S) URL. This is a strong malicious dropper/redirect indicator and is not expected in ordinary PDF content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.ygdyxx.com/Inc/admin/haha.htm
    • http://www.iec.ch

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
icc_00_off0000253f.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x253F 3144 bytes