Malicious PDF — malware analysis report

Static analysis result for SHA-256 bbf99062f2334eb1…

MALICIOUS

PDF

9.2 KB Created: 2009-02-19 14:45:49 -02:00 Authoring application: Writer (via OpenOffice.org 3.0)
MD5: 407892edea3de296f61df37753299671 SHA-1: 5c984a093247fe6c4e09dff693f7583da3a6ecd4 SHA-256: bbf99062f2334eb1e02fe3830a8c55039720f1ecb333b92d67ecce16a6d37b5f
100 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The PDF file contains an embedded URL that points to an executable file. The 'PDF_LAUNCH' heuristic indicates that the document is configured to launch an action, likely to download and execute the file from the provided URL. ClamAV detection further confirms the malicious nature of the file, identifying it as Pdf.Exploit.Agent-35541.

Heuristics 3

  • ClamAV: Pdf.Exploit.Agent-35541 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-35541
  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ac-trans.ru/exe/file.exeAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA