Malicious PDF — malware analysis report

Static analysis result for SHA-256 a13cec59719bb9d0…

MALICIOUS

PDF

235.8 KB Created: 2010-02-14 19:23:20 Authoring application: Joomla! 1.5 - Open Source Content Management (via TCPDF 2.5.000_PHP4 (http://www.tcpdf.org))
MD5: e928e26678f0e11b240be89a444d9ee7 SHA-1: cebd637938ef3d0dbb85cf4f0c539262fd865588 SHA-256: a13cec59719bb9d04ae6278ea73a3e51bdd9e1f89efe6077c11251aa90c67835
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a hidden external HTML iframe, indicating an attempt to redirect the user to malicious content. The ML classifier also flagged this PDF as malicious. The embedded URLs point to suspicious domains, likely serving malicious content or phishing pages. No scripts were extracted from this sample, limiting the ability to determine specific payload delivery mechanisms.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9482

Heuristics 2

  • PDF contains hidden external HTML iframe high PDF_HIDDEN_HTML_IFRAME
    PDF bytes contain a hidden zero-size HTML iframe pointing to an external HTTP(S) URL. This is a strong malicious dropper/redirect indicator and is not expected in ordinary PDF content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fuadrenal.com/lib/index.php
    • http://reycross.com/lib/index.php
    • http://odmarco.com/lib/index.php

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000b9ed.bin
a5337ef1f5a0dfe4dc8fa6b4f3ef847a53624800b5928a0eeef5b888ceecaabc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xB9ED 264072 bytes