Malicious PDF — malware analysis report

Static analysis result for SHA-256 01fd7ced34c9d2a9…

MALICIOUS

PDF

80.4 KB Created: 2021-03-30 11:57:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 568e97f5c5420e7af4542e515115207e SHA-1: e027d629be58c398997639cc1e406cf86155e579 SHA-256: 01fd7ced34c9d2a9a5e5a5a520e3d6ccb5cb26e7f707c2bace0ac74b0a1c38f9
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URL pointing to a suspicious domain, which is a common tactic for phishing or distributing further malicious content. The PDF structure itself is also flagged for duplicate object bodies, suggesting potential obfuscation or malformation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/aws?utm_term=deepak+chopra+21+days+of+abundance+day+16
    • https://cdn.sqhk.co/miburixegapu/ihqhcTJ/91492028166.pdf
    • https://cdn.sqhk.co/zidezofa/rSOgcie/bigeri.pdf
    • http://mulotaras.iblogger.org/can_i_add_apple_carplay_to_uconnect.pdf
    • https://cdn.sqhk.co/gijesali/xkjiPkk/rocket_launch_schedule_wallops_island.pdf
    • https://cdn.sqhk.co/gixedomawa/UPYhiEf/ben_coloring_10_ultimate_alien.pdf
    • https://cdn.sqhk.co/sixitigoxeto/jiDjb3V/best_rechargeable_battery_charger_2018.pdf
    • https://cdn.sqhk.co/rotogogoji/iXifPb3/jewetobidowibuwenomobezi.pdf
    • https://cdn.sqhk.co/jotenitix/ihejVVn/ninjago_season_12_episode_11.pdf
    • http://sigifiketatoge.22web.org/zexikotul.pdf
    • https://cdn.sqhk.co/wibezudak/eqid5gh/real_appeal_we_rally_login.pdf
    • https://cdn.sqhk.co/fuvebopeweb/eEYJzsR/dipomozeson.pdf
    • https://cdn.sqhk.co/raxuzuvuluf/hgjjEib/very_loud_ringtones_for_cell_phone.pdf
    • https://cdn.sqhk.co/bupewazadufa/jhjzFep/4924962299.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/gonafoziguwewe/acids_bases_ph_worksheet_continued_answers.pdf
    • https://s3.amazonaws.com/kabisebax/what_is_the_dead_sea_scrolls_doomsday_prophecy.pdf
    • http://pufaxutunipoja.epizy.com/mortgage_lenders_tri-_merge_credit_report.pdf
    • http://kugilib.rf.gd/75225224864.pdf
    • https://uploads.strikinglycdn.com/files/015065d8-c31b-4752-a6cb-f08a82f6ce23/vafewufezavokip.pdf
    • https://uploads.strikinglycdn.com/files/93d5df58-06e8-4363-8a5d-1e994cf8ecf9/what_does_2319_mean_from_monsters_inc.pdf
    • http://rovafitazilom.epizy.com/w3layouts_bootstrap_admin_templates.pdf
    • https://s3.amazonaws.com/meludav/34594914607.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d898.bin
ec40d242422264ef6ac78d1b5287b1bb2b6e02c0c8b79ee2053a48fd8d622861
pdf-font-stream PDF embedded font (sfnt) at offset 0xD898 5856 bytes
font_01_sfnt_off0000ec86.bin
7dcd68b79c5b3fe48e6d6db23daa59459fb689643d148e9cc2b1a76d22ecba0d
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC86 2756 bytes
font_02_sfnt_off0000f838.bin
97ace889b750e57ef56c648870e4c0a739f053f5606d090aa3c81402b6ab76e6
pdf-font-stream PDF embedded font (sfnt) at offset 0xF838 10584 bytes
font_03_sfnt_off00011cb3.bin
ee2cf55a7d349dba81c43c231b1bc7ea46bdbbb7d51755bb44167f04c70a0cbb
pdf-font-stream PDF embedded font (sfnt) at offset 0x11CB3 16136 bytes