Malicious PDF — malware analysis report

Static analysis result for SHA-256 0029bf8938e8f479…

MALICIOUS

PDF

77.4 KB Created: 2021-03-09 07:07:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4c63325c47625f91dbb584db32743509 SHA-1: 7083c1907fd48c60e3b298c68f7767485aefb5de SHA-256: 0029bf8938e8f47974ee58cad5ec607b55998036379c26d4c967e31500f7480f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9956

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/wix?keyword=legends+m1a1+full+auto+replica+bb+gun+.177
    • http://prizinsta24.online/mulegasebitibalebiv04en.pdf
    • http://reduslimitalia-official.site/slope_intercept_form_point_slope_form_worksheetpibqk.pdf
    • https://nubugudapo.weebly.com/uploads/1/3/2/8/132814946/lusuwakixozomixomu.pdf
    • https://zibefaxad.weebly.com/uploads/1/3/4/5/134594794/nuwonesab-segewusujuduwi-zamugibavog.pdf
    • http://daxuzenadisasib.iblogger.org/qu_es_una_introduccin.pdf
    • https://ridimejaxokixis.weebly.com/uploads/1/3/5/3/135340331/bobamuneg.pdf
    • https://saripubisopa.weebly.com/uploads/1/3/5/3/135322362/f163bd30b18add3.pdf
    • http://agentsoft.space/neregubijojavemaxog6te8.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://a12a05ab-6462-4855-b086-b0a2a961d6d8.filesusr.com/ugd/2c76f4_1a25f38cca9b4074b9f1d9674ab6c7ff.pdf?index=true
    • https://uploads.strikinglycdn.com/files/3e051df9-8558-449d-830e-55e0806add32/why_are_amazon_kindle_books_so_expensive.pdf
    • https://uploads.strikinglycdn.com/files/d7da6bc2-8c22-416f-9a13-06598ce93e78/matlab_exam_questions_and_solutions.pdf
    • https://uploads.strikinglycdn.com/files/3a35056c-9d2e-453b-86f7-06e0aa79fa8e/how_to_use_hoover_steamvac_dual_v.pdf
    • http://pasejisozud.rf.gd/95325968341.pdf
    • http://godutugogusapa.rf.gd/rixineveja.pdf
    • https://3b044092-e341-4c69-a8e2-52b14fc1865f.filesusr.com/ugd/370021_1748ef9b18734855a0c33c64f6acee26.pdf?index=true
    • https://uploads.strikinglycdn.com/files/2f5d97b1-47ab-452b-b243-1b7b11ab0945/is_oracal_631_removable.pdf
    • https://s3.amazonaws.com/xonaxevetaf/psychiatry_clerking_sheet.pdf
    • https://uploads.strikinglycdn.com/files/2d6c1979-6505-41df-8307-a84fd798d1c7/22129141464.pdf
    • http://norenebe.rf.gd/rotemagozulularu.pdf
    • https://1cf095b7-1d29-4152-b82c-7733cf7ba0c7.filesusr.com/ugd/c1de29_0481ea5d7847452fafb07dac79e62c21.pdf?index=true
    • https://s3.amazonaws.com/zesotat/terabagabirazexidumivas.pdf
    • http://mivoxonewume.rf.gd/recommendation_letter_template_for_student_teacher.pdf
    • https://s3.amazonaws.com/fajujiju/circulatory_system_worksheets_for_grade_3.pdf
    • https://s3.amazonaws.com/fejenijovekozu/2019_all_audio_songs_free.pdf
    • https://s3.amazonaws.com/kewuxejikiwe/zopobime.pdf
    • https://2dcb0092-dd22-4cef-90c1-8c398f802bb7.filesusr.com/ugd/ff3115_e85129f7ddf143c0ac3bee59d3099133.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0c3.bin
98ed987d1eec57d0561302faf7d486a76285e79a6511bce7af222004f242a73b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0C3 5720 bytes
font_01_sfnt_off00010433.bin
65c6de1890e625d661ff24e05a7aa1814389260c35fbb9f35691c349ab95ec03
pdf-font-stream PDF embedded font (sfnt) at offset 0x10433 10492 bytes