Malicious PDF — malware analysis report

Static analysis result for SHA-256 77c37435a60605c9…

MALICIOUS

PDF

276.7 KB Created: 2023-12-05 18:31:43 -02:00 Authoring application: ReportLab PDF Library - www.reportlab.com
MD5: 79dfc319a71d3f3fe14476bb9d0235c1 SHA-1: 9fbb7ed8eb780431b6bb3c70de4d2e1fe617e11d SHA-256: 77c37435a60605c9937f1d4cb1d63c5f2be447cc06d4ebad6cdc55cd574c5d41
68 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF document contains an embedded JavaScript stream and uses an ASCII85Decode filter, both common techniques for obfuscating malicious content. The ML classifier flagged this PDF as malicious with a high probability. The document is structured as an image-only lure, typical of phishing attempts, and contains a clickable external URI pointing to 'https://mardurasp.com/se/?fjLkWcdWofJCWzViUmCZnIBpsVLlGWmnNcUTKkGlDhFBcvCHzFeQglEvkfQLJQPyJrIHXtmLqWRwr'. This suggests the document's primary purpose is to redirect the user to a malicious website for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8465

Heuristics 5

  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 276 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85
    ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mardurasp.com/se/?fjLkWcdWofJCWzViUmCZnIBpsVLlGWmnNcUTKkGlDhFBcvCHzFeQglEvkfQLJQPyJrIHXtmLqWRwr
    • http://www.reportlab.com