Malicious PDF — malware analysis report

Static analysis result for SHA-256 bcd2f24863ff5ec2…

MALICIOUS

PDF

62.4 KB Created: 2016-03-18 10:33:25 +02:00 Authoring application: PScript5.dll Version 5.2 (via GPL Ghostscript 9.06)
MD5: 29d36d71a8d4410a2ba1d9c5227138dd SHA-1: ca82add91258ae7d2ee10c15c47b75bdd7c7cdd4 SHA-256: bcd2f24863ff5ec2cdc6f0a36f8eaa4bc463539ec32f04aa7402781157c403c3
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file is identified as malicious by ClamAV with the signature Pdf.Dropper.Agent-7217113-0. Static analysis heuristics indicate it is an advance-fee scam lure, commonly used to trick victims into paying fees for non-existent prizes or parcels. The document body is heavily obfuscated, preventing detailed content analysis, but the heuristic firings strongly suggest a social engineering attack.

Heuristics 2

  • ClamAV: Pdf.Dropper.Agent-7217113-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7217113-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0000e44f.bin
68fef29c8acb3d451119ce03f7e5077befc52ea4db96b789a9a40b8f3e94381c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xE44F 5320 bytes
font_00_cff_off00009847.bin
143b5e8edfe0047f014da23de4449881b82d7be908bd2f859e0a3b3fb4829b78
pdf-font-stream PDF embedded font (cff) at offset 0x9847 1225 bytes
font_01_cff_off00009eeb.bin
f60fc7a4d132f75c323a9478fe1fb298353ab97fb30e18740012f7aaf16a486a
pdf-font-stream PDF embedded font (cff) at offset 0x9EEB 7473 bytes
font_02_sfnt_off0000b964.bin
92e36f962de3ec6db9b67905429e3b2b8201ecfeb99405af4019af06bfe5844f
pdf-font-stream PDF embedded font (sfnt) at offset 0xB964 13836 bytes
font_03_cff_off0000dd3f.bin
b520f55294feb11bb58295252cae3dfbac2d51188969fbd88cb6c76ffbcf132a
pdf-font-stream PDF embedded font (cff) at offset 0xDD3F 1430 bytes