Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe69a7a77f3a7089…

MALICIOUS

PDF

205.2 KB Created: 2017-11-13 13:16:41 -08:00 Authoring application: Microsoft® Word 2016
MD5: f4e69c2c2c8085e1811dd6b993c9b58d SHA-1: 905c8493768146f7e7c086d3833b331e3c865f3e SHA-256: fe69a7a77f3a708949285a39fdcc01865c2a96cfb7b10aa2e56df5c10db9324f
80 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains embedded URLs, one of which uses a URL shortener (bit.ly). The ClamAV heuristic identifies this as a Pdf.Dropper.Agent, indicating it's designed to drop or redirect to malicious content. While the specific redirection target is not fully resolved due to the benign reputation of the bit.ly links themselves, the presence of a known dropper signature and the use of URL shorteners strongly suggest a malicious intent to lure the user to a harmful site.

Machine Learning

  • Nyx PDF Classifier clean score 0.0004

Heuristics 3

  • ClamAV: Pdf.Dropper.Agent-7328912-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7328912-0
  • Clickable URI uses URL shortener medium PDF_URL_SHORTENER_URI
    PDF contains a clickable HTTP(S) action whose destination is a URL shortener. This hides the final landing page from static review and is common in phishing redirect PDFs.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bit.ly/2tkLNBQ
    • http://bit.ly/2zE6mhV
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000057ab.bin
ef0f7fc15ea0cd9d4439dbf95fb2c8e1452fa179b382733e9a703b8247cb0bfc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x57AB 198380 bytes
stream_005_off0001c2a5.bin
fbd1542d1f330ffb194bf8450c425b7425f7268d39ce66ce0d160296b9cc3a3f
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1C2A5 300604 bytes