Malicious PDF — malware analysis report

Static analysis result for SHA-256 e21d15172dd7e5d9…

MALICIOUS

PDF

208.6 KB
MD5: 8bc98a571308d393bc5d009f02cb1371 SHA-1: 8674ac73f74f93346e7a2ad5d459168ff07e881e SHA-256: e21d15172dd7e5d969f8ca12fa93a295ff008fcb98d9e9f1b7bbe2349f0d08ed
62 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The file is a PDF document identified by ClamAV as Win.Exploit.Unicode_Mixed-1, indicating it likely exploits a known PDF vulnerability. An external URI pointing to a LinkedIn profile was extracted, though it is marked as benign. The document body contains heavily obfuscated content, preventing a deeper analysis of its specific lure or payload delivery mechanism.

Heuristics 3

  • ClamAV: Win.Exploit.Unicode_Mixed-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Exploit.Unicode_Mixed-1
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.linkedin.com/pub/joseph-slowden/43/47/500