Malicious PDF — malware analysis report

Static analysis result for SHA-256 faaa8dc5cca7dc43…

MALICIOUS

PDF

304.1 KB Created: 2017-08-16 13:22:56 +03:00 Authoring application: ojey862q (via TCPDF 6.2.13 (http://www.tcpdf.org))
MD5: b1d947bcf8d5739a963d5d400c669521 SHA-1: a9d09fa6c382bba8ffe138aa7770580a3bc7c32a SHA-256: faaa8dc5cca7dc43f2f8a30f8e02922b0dc823010f851fe25e7ab431c87b1d0d
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as a malicious PDF by ClamAV. It contains an embedded URI pointing to 'http://afmoon.com/tds/800u', which is flagged as suspicious. The PDF structure and embedded artifacts suggest it's designed to exploit vulnerabilities or trick users into visiting the malicious URL, likely to download further malicious content.

Machine Learning

  • Nyx PDF Classifier clean score 0.0009

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7327043-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7327043-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://afmoon.com/tds/800u PDF link annotation
    • http://www.tcpdf.orgIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.aiim.org/pdfa/ns/extension/In PDF document text
    • http://www.aiim.org/pdfa/ns/schema#In PDF document text
    • http://www.aiim.org/pdfa/ns/property#In PDF document text
    • http://www.aiim.org/pdfa/ns/id/In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000a612.bin
a217f12862e0ff75203bdd4136ca0d68471050be46bb09aed5306898926ffdd4
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xA612 120140 bytes