Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae2b53f6d1a34eef…

MALICIOUS

PDF

512.7 KB Authoring application: Viraciregavi
MD5: 1565948572e9ddb49eff171ad76f90e8 SHA-1: 19c66ad2c93f27d35760fe87b62449ec287331c0 SHA-256: ae2b53f6d1a34eeff88e6ca413098d7a5da343e4ea3b7982b25246553e553aed
66 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains embedded JavaScript and a callback phishing lure, indicating a malicious intent to deceive the user. The ML classifier strongly flagged this PDF as malicious. While the JavaScript's exact function is not fully discernible due to obfuscation, its presence alongside the callback lure suggests it is used to facilitate the scam, likely by downloading or executing a secondary payload. The embedded URL 'http://ns.InsiderSoftware.com/fontlist/1.0/' is of unknown reputation and warrants further investigation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9571

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.InsiderSoftware.com/fontlist/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
icc_00_off00041d27.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x41D27 3144 bytes
font_00_sfnt_off00003d7e.bin
5f96e1e90c4ef56487c91d02c05141dca0967f8e2bbd5d67be6c4f381f0afa79
pdf-font-stream PDF embedded font (sfnt) at offset 0x3D7E 62160 bytes
font_01_sfnt_off0000d1d4.bin
b661c2e877dd6b7625208ae148d736aedb24eda2d4f014262cbb7f958f538ca0
pdf-font-stream PDF embedded font (sfnt) at offset 0xD1D4 71216 bytes
font_02_sfnt_off0001a22f.bin
8b62f203a4ab5c2ac76368029c584b4fa12fffc17f3b6e4e43a9997416807d21
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A22F 11156 bytes
font_03_sfnt_off0001c1e0.bin
d375c22ace40f0b973d7308d85023b2e0e49d40dc51da45552d116868346475e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C1E0 37232 bytes
font_04_sfnt_off00023037.bin
afeb9e1e920aae3aca3f295f1bbccba46b16423dac14b1b5fde4b661de9198cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x23037 46764 bytes
font_05_sfnt_off0002b8b2.bin
95592346b00d039686aa3d7e22eae3d52b011e7e842a5c123f73e89ea766cd35
pdf-font-stream PDF embedded font (sfnt) at offset 0x2B8B2 22628 bytes
font_06_sfnt_off00037959.bin
6cf6df6beee88aa138f821122d0c1969b348cebe09cafe5b5f6a7eb8c27107a0
pdf-font-stream PDF embedded font (sfnt) at offset 0x37959 32640 bytes