Malicious PDF — malware analysis report

Static analysis result for SHA-256 f16bf41a48652474…

MALICIOUS

PDF

54.6 KB Created: 2007-06-22 15:18:31 -07:00 Authoring application: Adobe InDesign CS2 (4.0) (via Adobe PDF Library 7.0)
MD5: 57b4010217e91a078f11656443810ce7 SHA-1: 8b7e9b53ae38b26953ee7ccc156d554bab4829ea SHA-256: f16bf41a4865247421f9bbed730981dfbe21f47d743f0e2831c1dbebca363334
128 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The primary indicator of maliciousness is the critical ClamAV detection of the EICAR test signature, both directly and within an embedded artifact. This confirms the file's nature as a test case for security software. No other malicious indicators were found.

Heuristics 4

  • ClamAV: Eicar-Test-Signature critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Eicar-Test-Signature
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/g/img/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
eicar.com
275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f
pdf-embedded-file PDF EmbeddedFile object 36 at offset 0xD6D0 68 bytes
Detection
ClamAV: Eicar-Test-Signature
Obfuscation or payload: unlikely