Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5ab6c976c54014c…

MALICIOUS

PDF

52.8 KB Created: 2017-11-13 09:27:45 +00:00 Authoring application: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 (via Skia/PDF (via pdfcrowd.com))
MD5: f2814cf1eba588b725ab3e6752fd3e2d SHA-1: 50a2b0b55d1bd31c859c6f0a2440bd56e0233f71 SHA-256: b5ab6c976c54014c53280f67314cbd23a127c007e02c391ccc60e55de749d561
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is identified as a malicious PDF by ClamAV. It contains multiple embedded URLs, including one pointing to 'hotelhonolulu.com.gt', which is flagged as suspicious. The presence of these links suggests a phishing or redirection attempt to a malicious site. No scripts were extracted, limiting the analysis of specific behaviors.

Machine Learning

  • Nyx PDF Classifier clean score 0.0856

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7295421-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7295421-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.hotelhonolulu.com.gt/.dep/redirect.html
    • http://ceneinnova.com/ajj/ndb/index.php
    • https://pdfcrowd.com/doc/api/?ref=pdf
    • https://pdfcrowd.com/?ref=pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003d27.bin
de895ed87772da48ab0e4f566fe41384afbc59e782d7828e777863d12fd943f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x3D27 42844 bytes
font_01_sfnt_off00009b9a.bin
5091de8b5a8651ee3354927cb3e58ac938a47a05778b1c5b3dcda2384521acca
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B9A 21532 bytes