Malicious PDF — malware analysis report

Static analysis result for SHA-256 85b74193faca9303…

MALICIOUS

PDF

16.2 KB Created: 2018-10-03 16:47:02 +03:00 Authoring application: dompdf + CPDF
MD5: e970e6501491207b741aa99967be3258 SHA-1: bc0a813ae94004afb981fe3bc0bc31cd685132a3 SHA-256: 85b74193faca93034dce1cfc693208ee5d318d5ae4378e69b35420d85b518e88
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains heuristics indicating it is a malicious dropper and uses language suggestive of a payment lure. It embeds a URL that likely leads to a malicious payload. Although no scripts were explicitly extracted, the PDF structure and embedded URL strongly suggest a malicious intent to download and execute further stages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7756

Heuristics 5

  • ClamAV: Pdf.Dropper.Agent-7278806-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7278806-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kantauri.com/3180HCL/identity/Commercial

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off00000297.bin
cc6bf9cc027488b7e78196fdfdcb6616991c42c47767930b4046d841b32008e1
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x297 17876 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 16 long base64-like blob(s).