Malicious PDF — malware analysis report

Static analysis result for SHA-256 e86d08b53fbda9fd…

MALICIOUS

PDF

1.05 MB Created: 2010-09-11 22:09:35 Authoring application: Joomla! 1.5 - Open Source Content Management (via TCPDF 2.5.000_PHP4 (http://www.tcpdf.org))
MD5: 78d8f2836b8462e74ca99440cd823c7e SHA-1: 923ad590ce48e860b84433b056617bb0be7806ad SHA-256: e86d08b53fbda9fd24fa8c7edfad18ad977f1ae21b399d992ba911eaf4acc021
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a hidden HTML iframe, a common technique for redirecting users to malicious sites. ClamAV detected this file as Html.Spyware.IMG-7, indicating a known malicious signature. The embedded URL points to an unknown but potentially malicious domain, which is likely the target of the iframe redirection. The file's structure and the heuristic firings suggest it's designed to lure the user to a compromised site.

Heuristics 3

  • ClamAV: Html.Spyware.IMG-7 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Html.Spyware.IMG-7
  • PDF contains hidden external HTML iframe high PDF_HIDDEN_HTML_IFRAME
    PDF bytes contain a hidden zero-size HTML iframe pointing to an external HTTP(S) URL. This is a strong malicious dropper/redirect indicator and is not expected in ordinary PDF content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.codeforum.cn/free/max1.htm
    • http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/iX/1.0/
    • http://ns.adobe.com/exif/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://www.iec.ch

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000b97b.bin
a5337ef1f5a0dfe4dc8fa6b4f3ef847a53624800b5928a0eeef5b888ceecaabc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xB97B 264072 bytes