Malicious PDF — malware analysis report

Static analysis result for SHA-256 0257d76098a75332…

MALICIOUS

PDF

74.5 KB Created: 2021-03-22 05:07:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 579fd283d03a11f3ce535eec828fda61 SHA-1: 4285f3e8e1bf9cf0fcb0151faf8a290b9810473e SHA-256: 0257d76098a75332f20126abc4eaa62e276f98e7b93a5b7cefb04093b8072418
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains an embedded URI pointing to a suspicious domain, identified as malicious by ML classifiers and ClamAV. The embedded URL suggests a phishing attempt, likely to trick the user into downloading further malicious content or providing sensitive information. No scripts were extracted, but the presence of external links and the high risk score indicate a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/award?keyword=factors+affecting+the+climate+pdf
    • https://cdn.sqhk.co/godereliku/Bjggdhd/is_don_martindale_wink_martindale_s_son.pdf
    • https://cdn.sqhk.co/tupizurelir/ijigrXJ/scary_costumes_for_halloween_for_adults.pdf
    • https://cdn.sqhk.co/xolokenuw/icaSNja/super_jungle_world_adventure_games.pdf
    • https://cdn-cms.f-static.net/uploads/4391000/normal_6031d5f2af88a.pdf
    • https://static.s123-cdn-static.com/uploads/4423137/normal_5febf092ceb6e.pdf
    • https://static.s123-cdn-static.com/uploads/4377407/normal_6002c46d6a98c.pdf
    • https://cdn-cms.f-static.net/uploads/4420260/normal_6028c11582192.pdf
    • https://cdn-cms.f-static.net/uploads/4413977/normal_60270ebd78306.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/4de95ac0-54a1-4d92-aa29-bb8844e8122f/3129704511.pdf
    • https://uploads.strikinglycdn.com/files/873898a0-b78d-4bcc-bea2-4dce0b77ee16/xasimef.pdf
    • https://uploads.strikinglycdn.com/files/3171efa5-cc37-483f-9e7e-38be63e54954/what_is_the_difference_between_a_route_and_an_interstate.pdf
    • https://uploads.strikinglycdn.com/files/2e5df2e6-432d-4790-ac28-031968e27418/revolution_2020_full_movie.pdf
    • https://uploads.strikinglycdn.com/files/6fd1bbb1-09d6-41d9-a313-277d43cb8c87/ford_3000_tractor_hp.pdf
    • https://uploads.strikinglycdn.com/files/cdb90b2f-061f-46bb-8fc7-6b7b4c995899/what_is_active_and_passive_voice_with_examples.pdf
    • https://uploads.strikinglycdn.com/files/6cd3dd81-39f6-4aa6-8030-1f12293311da/foliditunavikepiro.pdf
    • https://uploads.strikinglycdn.com/files/ba51d3e1-3027-489d-981c-582a717aec44/96715764302.pdf
    • http://kaxixuzebupajal.epizy.com/biderivavatapemu.pdf
    • https://uploads.strikinglycdn.com/files/4a342b52-69b9-4134-b443-86a3be5201fa/chronicle_of_a_death_foretold_themes_essay.pdf
    • http://botiditab.rf.gd/how_to_update_a_mod_sims_4.pdf
    • https://uploads.strikinglycdn.com/files/bd35d04d-4bd7-45f4-8352-63f0358159fe/causes_of_the_great_depression_definition.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e851.bin
cac237158552cb301232c00860c154fbac192e789dbe00ea33905dea0b106d01
pdf-font-stream PDF embedded font (sfnt) at offset 0xE851 5524 bytes
font_01_sfnt_off0000faf0.bin
f4c75aec3f892b29d500b3f7501980c068d398149a75b8019f80a8d4461b1a13
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAF0 9832 bytes