Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba4524db98981b2b…

MALICIOUS

PDF

4.8 KB Created: 2018-09-11 17:46:02 +03:00 Authoring application: dompdf + CPDF
MD5: 793e2c3dc3e623e446184c7767963310 SHA-1: 6270ecb37e240fcfb2eb56a6cd26127cbc313a73 SHA-256: ba4524db98981b2be4eef14b4fcb309c38a79596d2c5ff990ccc275c90dba5d4
72 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a SE_INVOICE_LURE heuristic, indicating it is designed as a fake invoice to trick the user. It also embeds a URL, http://diaoc365.xyz/Document/US_us/Invoice-receipt, which is likely used to deliver a secondary payload. The ClamAV detection 'Pdf.Dropper.Agent-7296669-0' further confirms its malicious nature as a dropper.

Heuristics 5

  • ClamAV: Pdf.Dropper.Agent-7296669-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7296669-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://diaoc365.xyz/Document/US_us/Invoice-receipt

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off00000268.bin
17ae8afd23213c7c3c2a79485f8d6c9a5da306617b744bb1937f08917db984da
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x268 5449 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 15 long base64-like blob(s).