MALICIOUS
146
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF is encrypted and appears to be image-only, a common lure technique. Heuristics indicate a payment redirection lure, suggesting a business email compromise attempt. ClamAV detected the file as Pdf.Dropper.Agent-6308054-0, confirming its malicious nature. No scripts were extracted, limiting the ability to determine the exact payload delivery mechanism.
Machine Learning
- Nyx PDF Classifier suspicious score 0.4509
Heuristics 6
-
ClamAV: Pdf.Dropper.Agent-6308054-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Dropper.Agent-6308054-0
-
Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LUREDocument describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
-
Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISHDocument impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://www.funnynames.com/..
-
Encrypted PDF (string and stream contents are opaque to static scan) info PDF_ENCRYPTEDPDF declares /Encrypt — string objects and stream contents are encrypted with the standard security handler (RC4 or AES). On its own this is informational; legitimate encrypted documents include signed contracts, billing statements, and rights-managed material. Static heuristics cannot inspect encrypted payload bytes.
-
PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILEDThe cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: error. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.funnynames.com/ In PDF document text
- http://www.aspkin.com/forums/In PDF document text
- http://www.aspkin.com/forums/ebay-tracking/In PDF document text
- http://www.aspkin.com/forums/phone-In PDF document text
- http://www.aspkin.com/forums/merchant-accounts/In PDF document text
- http://ocsp.verisign.com0In PDF document text
- http://mail.google.com/mail/signupIn PDF document text
- http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
- http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
- http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
- http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
- http://www.microsoft.com/typographyIn PDF document text
- http://www.monotype.com/html/mtname/ms_symbol.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATIONIn PDF document text
- http://www.monotype.com/html/type/license.htmlIn PDF document text
- http://crl.verisign.com/ThawteTimestampingCA.crl0In PDF document text
- http://crl.verisign.com/tss-ca.crl0In PDF document text
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0OIn PDF document text
- http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0In PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_010_off00032be7.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x32BE7 | 96000 bytes |
SHA-256: b791c53898135d1a0764159221f88707f7bb9d14f2d13d6d2c430d5d3100f456 |
|||
stream_038_off000e8af5.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xE8AF5 | 206760 bytes |
SHA-256: ebf35e9e19bdd2fdcf7ac43c09aa03f7c96339392dbf06f2d5c4076bade5f191 |
|||
font_00_sfnt_off000f5ed5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF5ED5 | 24332 bytes |
SHA-256: ca6c494bb5ef9be7361cfad38425c9e5ec46bc51a29f0a9ed3e0b4866540a7f4 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.