Malicious PDF — malware analysis report

Static analysis result for SHA-256 84d36e52aba8425d…

MALICIOUS

PDF

8.7 KB Created: 2016-02-21 14:44:42 -07:00 Authoring application: wkhtmltopdf
MD5: c45a57bcf9e2a724f0cb64bf1f0a5bb4 SHA-1: 1d438df666a665d36b2eeebc10789020edff8abe SHA-256: 84d36e52aba8425d1c2bde3e155ba77c07533595c611b122b9608006d6036e0a
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF is identified as a phishing lure by heuristics, presenting a fake DHL notification to prompt a user click. The embedded URL, http://bit.ly/1QuGAQQ?DHL=3&HTTP://DHL.COM=DHL_IV/BL/TRACKING_NUMBER, leads to a URL shortener, a common tactic in phishing campaigns. ClamAV detection further confirms its malicious nature as Pdf.Dropper.Agent-7278545-0.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5168

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7278545-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7278545-0
  • Image-only PDF lure links through URL shortener high PDF_IMAGE_LURE_SHORTENER_LINK
    PDF is image-heavy with little real text and its clickable action points to a URL shortener. This is a high-confidence credential-phishing carrier shape: the visible page is a screenshot-like prompt while the destination is hidden behind redirect infrastructure.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 8 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bit.ly/1QuGAQQ?DHL=3&HTTP://DHL.COM=DHL_IV/BL/TRACKING_NUMBER

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000a71.bin
524a0e8e6bb3ced4b9ea9ae58dbcce65d81916444a98e5e35997117136776251
pdf-font-stream PDF embedded font (sfnt) at offset 0xA71 3928 bytes
font_01_sfnt_off00001b6d.bin
43ae419872ec41b206087f18b3def1bb47a5f8b42e2c6b67c50ce0b678496d77
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B6D 748 bytes