Malicious PDF — malware analysis report

Static analysis result for SHA-256 fbd611fdeb0cf1be…

MALICIOUS

PDF

103.1 KB Created: 2020-10-26 20:49:39 +03:00 Authoring application: Stephanie Davis (via Patrick Ward Jr. Sr. I II III IV V MD DDS PhD DVM)
MD5: 12e6a1898f919cc210143779a5e0c8d4 SHA-1: f17f4ac23e5d3220c0ac2b116750ca2f99e71369 SHA-256: fbd611fdeb0cf1be732bdac95ada0f66cc235060e5b9769340cf123f99b70ddf
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious Link

The PDF exhibits characteristics of a phishing lure, being image-only with a click-outward action. Heuristics indicate it contains external URIs and a local builder path, suggesting it's intended to redirect the user to malicious content. The presence of multiple embedded URLs further supports this. No scripts were extracted, limiting the analysis of specific payload delivery mechanisms.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4213

Heuristics 4

  • Image-only PDF carries local builder path plus remote links high PDF_IMAGE_LURE_LOCAL_FILE_AND_REMOTE_URI
    PDF is an image-only click lure that contains both remote HTTP(S) destinations and a file:/// URI exposing a local Windows/Linux builder path. That co-occurrence is not normal document linking; it matches generated clickbait/phishing carriers where the visible page is a screenshot and the clickable area sends the user to external infrastructure.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 103 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dgwpz7s.cjv
    • http://hlh9g2j.sed.macabrepoe.com