Malicious PDF — malware analysis report

Static analysis result for SHA-256 f55e90b6fa22af99…

MALICIOUS

PDF

121.8 KB Created: 2017-01-27 10:29:28 +01:00 Authoring application: RAD PDF (via RAD PDF 2.38.3.1 - http://www.radpdf.com)
MD5: b5f75f68772aa56d44a6b0f8acb6bb93 SHA-1: e5ab164052f47cd9b3e0ea543e4ea1b92c01a3fe SHA-256: f55e90b6fa22af99afca344b5fbb764872c9cf302b518bbb7ad3d792f4ff4b9f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains multiple invisible and repeated links pointing to a Dropbox URL which hosts a ZIP archive. This archive likely contains a malicious payload, as indicated by the ClamAV detection and ML classifier. The presence of a batch file URL alongside the ZIP suggests a multi-stage infection process.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8491

Heuristics 3

  • Invisible/repeated PDF links deliver payload file critical PDF_REPEATED_PAYLOAD_LINK_LURE
    PDF uses invisible link annotations and points to a direct payload download. Repeated invisible links or lure-like payload names such as document/unlock/verify archives match malware-delivery PDF carriers where the page is only a prompt and the real payload is fetched from the linked URL.
  • ClamAV: Pdf.Dropper.Agent-7324189-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7324189-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.dropbox.com/s/q2pxyat76300fhz/BANK%20DRAFT%20COPY1.zip?dl=1
    • https://www.dropbox.com/s/mu522ez45ll725z/DUE%20OUTSTANDING%20INVOICES.bat?dl=1
    • http://www.radpdf.com)/Creator(RAD
    • http://www.dynaforms.com
    • http://www.radpdf.com
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000006c5.bin
211db2fe9b00da0769dc17e36faecacd3316fd1da82722127767ca9a55753e64
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C5 98205 bytes