Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5cae9ee72e09097…

MALICIOUS

PDF

39.2 KB Created: 2015-08-28 01:59:38 +03:00 Authoring application: 1 (via Softplicity)
MD5: 34bdb331204a71dc02f8a99f1ca53af2 SHA-1: 7c3ea90e623ffa614ee7f7b1b4cef0251f6ecaa0 SHA-256: e5cae9ee72e09097540c04f17a05c0355ea39b080b75b5b0ae2063050a8e82b5
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains an embedded URL that redirects to a download script, as indicated by the PDF_URI heuristic and the presence of the URL in the document body. The ClamAV detection 'Pdf.Dropper.Agent-7602139-0' strongly suggests this file is a dropper. The document body text, while containing service manual information, also includes the malicious URL, reinforcing the lure. The primary intent appears to be downloading and executing a second-stage payload from the identified URL.

Machine Learning

  • Nyx PDF Classifier clean score 0.0465

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7602139-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7602139-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://download.tomsorg.com/get.php?q=Hp
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00002f34.bin
0ec7f9ab4d1c99ee3ff97c500fc37028052b2a9188043be44ae2f7464b17889d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2F34 20804 bytes
font_01_sfnt_off000067a3.bin
22b4cd0ea5cb7f5d2f07393fb0a69a43ea3e3422e38551f6cb582797c552bfa5
pdf-font-stream PDF embedded font (sfnt) at offset 0x67A3 16864 bytes