Malicious PDF — malware analysis report

Static analysis result for SHA-256 9aeda093235ab026…

MALICIOUS

PDF

59.3 KB Authoring application: http://www.convertapi.com
MD5: 1b0cda424f2e414d1c5bfc40f0ac2fa4 SHA-1: 31f3f241b665b35ccc47ad370272ffed0b1cf38b SHA-256: 9aeda093235ab026fe56dfbf784e82268171b5f23d1805b3a5378e7014d7c86a
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF employs an image-only lure, a common tactic to trick users into interacting with a malicious link. The heuristic 'PDF_IMAGE_LURE' indicates a screenshot-like appearance with an action trigger. The embedded URI 'http://admin.sigmacell.in/skin/index.php' is identified as a potential target for this lure. ClamAV detection further confirms the malicious nature of the file, classifying it as 'Pdf.Dropper.Agent-7286030-0'.

Machine Learning

  • Nyx PDF Classifier clean score 0.0040

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7286030-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7286030-0
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 0 text block(s), carries a click-outward action, and is only 59 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.convertapi.com
    • http://admin.sigmacell.in/skin/index.php
    • http://www.web2pdfconvert.com?ref=PDF

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cf75.bin
d6808d4902dc7904128587c4f701e3b0d94ed2222ab4e4108d435dc089e36460
pdf-font-stream PDF embedded font (sfnt) at offset 0xCF75 2704 bytes
font_01_sfnt_off0000daa2.bin
095828a3bcb18c426cd83ceb92562d8c67ff930045cc612655f4f85940198162
pdf-font-stream PDF embedded font (sfnt) at offset 0xDAA2 4768 bytes