Malicious PDF — malware analysis report

Static analysis result for SHA-256 b61c24cd495ddc18…

MALICIOUS

PDF

20.0 KB Created: 2021-06-09 11:18:00 +03:00 Authoring application: JasperReports Library version 6.13.0-46ada4d1be8f3c5985fd0b6146f3ed44caed6f05 (via iText 2.1.7 by 1T3XT) First seen: 2021-06-17
MD5: 6f83deed04ed3539235b7c0f4570d811 SHA-1: 55e0f84f02b98fa2f5965a2250e89e7b63830c10 SHA-256: b61c24cd495ddc18476a5d5758e19cc3254ef6656e787533d5e17fdbbe2c86b5
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1078.003 Credentials from Password Stores T1219 Remote Access Software

The PDF contains a UNC path, identified by the heuristic CVE_2018_4993, which is a strong indicator of an attempt to steal NTLM credentials. The PDF_GOTO_REMOTE heuristic further suggests malicious intent by attempting to redirect the user. While no scripts were extracted, the presence of these specific PDF-related heuristics points towards credential harvesting.

Machine Learning

  • Nyx PDF Classifier clean score 0.0106

Heuristics 3

  • UNC path in PDF — possible NTLM credential theft (CVE-2018-4993/CVE-2019-7089) high CVE likely CVE_2018_4993
    PDF contains a UNC path (\\server\share) alongside action triggers — when a vulnerable viewer resolves this path, Windows may send NTLM credentials to the remote host as the matching PDF action is processed
  • Remote GoTo action high PDF_GOTO_REMOTE
    PDF references an external document via GoToR/GoToE whose target is a URL, UNC path, or executable
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL \\127.0.0.1\test In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000005e0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5E0 54236 bytes
SHA-256: 2f8ea1ecd6f45a38d53b2dd7ec3c8033b5a9e06c9ac1113c15e158de1637172a