Malicious PDF — malware analysis report

Static analysis result for SHA-256 fb676b03216484ac…

MALICIOUS

PDF

55.6 KB Created: 2017-11-05 08:12:32 +16:12 Authoring application: WPS Office
MD5: 15ba6877cabeee521412d64dcc0a4d53 SHA-1: 77f985a681f4c486835d290bcf9b49131851fb69 SHA-256: fb676b03216484acc7c8a1b33a15fdd95fdd33947ba100b96dd4742ce1becab8
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was detected as malicious by ClamAV with the signature Pdf.Dropper.Agent-7327413-0. It contains an embedded URI pointing to http://u.to/JphSEA, which is likely intended to redirect the user to a malicious site for further exploitation or payload delivery. The presence of an embedded URI and the ClamAV detection strongly suggest a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.0008

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7327413-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7327413-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://u.to/JphSEA

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003135.bin
a1c27c852f0bf9f42da9f9aa8b766367b1c0f0782a3416a09211d51469dd631c
pdf-font-stream PDF embedded font (sfnt) at offset 0x3135 65476 bytes
font_01_sfnt_off00007bb0.bin
662a65dcb4200b488a38b6a42f72dea6c7fcef5644f79c1fa5663175da2e2344
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BB0 62040 bytes