Malicious PDF — malware analysis report

Static analysis result for SHA-256 f05ad94644cebe6a…

MALICIOUS

PDF

936.8 KB Created: qÂ'Ö§=íDFP«0.¡¯ m=²ì›?^t¯ù¤ö{tÕ¹¨»ó©— Authoring application: ¾"%-Ã{ƒ!›À0,Ô{'m0› øCöqå±ñ®?ë6‹§ L–vºzÝqFØ>ôÇ7Í:w[ð@oiՅ˜¸e (via ìÌ7‰ÿÒm'eõL¡ÚÈ"At{¡zò,ÝZé3æ›MžÝ—"ôÇ{DzaTb9èðZ Ji澨) First seen: 2020-09-04
MD5: 6560629073cbbe93a57fa5a1515d6507 SHA-1: 35671150a4f1e4e41f3a4f2cffac4937a1f0b5aa SHA-256: f05ad94644cebe6a544d8e0035e746bcaefa88382c228331421571eda2ebe6a6
146 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF is encrypted and appears to be image-only, a common lure technique. Heuristics indicate a payment redirection lure, suggesting a business email compromise attempt. ClamAV detected the file as Pdf.Dropper.Agent-6308054-0, confirming its malicious nature. No scripts were extracted, limiting the ability to determine the exact payload delivery mechanism.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4509

Heuristics 6

  • ClamAV: Pdf.Dropper.Agent-6308054-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-6308054-0
  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://www.funnynames.com/..
  • Encrypted PDF (string and stream contents are opaque to static scan) info PDF_ENCRYPTED
    PDF declares /Encrypt — string objects and stream contents are encrypted with the standard security handler (RC4 or AES). On its own this is informational; legitimate encrypted documents include signed contracts, billing statements, and rights-managed material. Static heuristics cannot inspect encrypted payload bytes.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: error. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.funnynames.com/ In PDF document text
    • http://www.aspkin.com/forums/In PDF document text
    • http://www.aspkin.com/forums/ebay-tracking/In PDF document text
    • http://www.aspkin.com/forums/phone-In PDF document text
    • http://www.aspkin.com/forums/merchant-accounts/In PDF document text
    • http://ocsp.verisign.com0In PDF document text
    • http://mail.google.com/mail/signupIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text
    • http://www.monotype.com/html/mtname/ms_symbol.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATIONIn PDF document text
    • http://www.monotype.com/html/type/license.htmlIn PDF document text
    • http://crl.verisign.com/ThawteTimestampingCA.crl0In PDF document text
    • http://crl.verisign.com/tss-ca.crl0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0OIn PDF document text
    • http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0In PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_010_off00032be7.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x32BE7 96000 bytes
SHA-256: b791c53898135d1a0764159221f88707f7bb9d14f2d13d6d2c430d5d3100f456
stream_038_off000e8af5.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xE8AF5 206760 bytes
SHA-256: ebf35e9e19bdd2fdcf7ac43c09aa03f7c96339392dbf06f2d5c4076bade5f191
font_00_sfnt_off000f5ed5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF5ED5 24332 bytes
SHA-256: ca6c494bb5ef9be7361cfad38425c9e5ec46bc51a29f0a9ed3e0b4866540a7f4