Malicious PDF — malware analysis report

Static analysis result for SHA-256 a86f5483eddd6736…

MALICIOUS

PDF

13.3 KB Created: 2021-06-22 22:18:15 +02:00 Authoring application: Writer (via LibreOffice 7.0) First seen: 2021-06-30
MD5: 020974db112e70263d70778a2502be14 SHA-1: 74de0d1c30c26d73c3bf853bcdbdcb3a8b213ffb SHA-256: a86f5483eddd6736bf43cec2b081de47747bb711be772d9ecb4c21e26b17907f
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF contains an embedded file named 'info.doc', which is highly suspicious given the 'ML_NYX_PDF_MALICIOUS' and 'EXTRACTED_FILE_STATIC_TRIAGE' heuristics. The embedded file likely serves as a secondary payload, and the presence of an unknown URL suggests a potential download or command-and-control channel. The malformed stream length also indicates an attempt to obfuscate malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9100

Heuristics 5

  • Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://copec.cf/bekkw83qccilyc64######################################################################################################################### In PDF document text
    • http://schemas.openxmlformats.org/drawingml/2006/mainIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
info.doc pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x6A 36864 bytes
SHA-256: 18fe02e4ab29f2d79fdc9d17c3b921f7a5d1ca0be0287a5aa3d093f44f3f50df
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.