Malicious PDF — malware analysis report

Static analysis result for SHA-256 04cd8c4a7c711e26…

MALICIOUS

PDF

70.9 KB Created: 2021-05-06 22:16:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 21ed094f20affbd86bd8b680571ddcf8 SHA-1: 77dcb4abfd01757c3b6ab7b39c6c5a18e9896c2c SHA-256: 04cd8c4a7c711e26bce30510274d72acbe8a8f7d1e9e7ca420206a555ea8272c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The ML classifier and ClamAV detection strongly indicate maliciousness. The PDF contains embedded URLs that point to potentially malicious PDF files hosted on compromised websites. While no scripts were explicitly extracted, the presence of embedded URLs and the nature of the detection suggest this PDF is designed to redirect users to malicious content, likely for phishing or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.sunarozlem.com.tr/wp-content/plugins/super-forms/uploads/php/files/bdmps1sul0tfpik9nu5s3f3kr3/46399101047.pdf In PDF document text
    • http://www.iso-clean.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1607074741d3b9---91562446521.pdfIn PDF document text
    • http://modnyi-buket.ru/uploads/files/maserowowaxolilojoromap.pdfIn PDF document text
    • http://adanateknikservis.web.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16077c7064ded9---vivikoluj.pdfIn PDF document text
    • https://www.opdrrustukalac.com/wp-content/plugins/formcraft/file-upload/server/content/files/16082f47916479---55804624202.pdfIn PDF document text
    • https://www.hotel-palladium.gr/wp-content/plugins/super-forms/uploads/php/files/up4ethq0l9d9o4u02ftbj39uio/85723056042.pdfIn PDF document text
    • https://eyetracking.pl/userfiles/file/7659053463.pdfIn PDF document text
    • http://brandnewgoods.net/userfiles/file/16076105890.pdfIn PDF document text
    • https://getlovebooks.com/wp-content/plugins/super-forms/uploads/php/files/5e73b4a4b1bdd8b6d224470a9563ebaa/91369614224.pdfIn PDF document text
    • http://www.risingstars.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/16071408eac144---63417654231.pdfIn PDF document text
    • http://www.yourhealthyourchoice.org/wp-content/plugins/formcraft/file-upload/server/content/files/16078b945b95de---suzepi.pdfIn PDF document text
    • http://www.gainerwindows.ca/wp-content/plugins/super-forms/uploads/php/files/g17cqun1jujpo4q6omph78pmb1/3506292246.pdfIn PDF document text
    • http://iideree.org/wp-content/plugins/formcraft/file-upload/server/content/files/16086c946662e2---52200706941.pdfIn PDF document text
    • https://www.eziblank.com/wp-content/plugins/super-forms/uploads/php/files/b3u0fkkt4qd56dgu5hlkc7id50/86159177134.pdfIn PDF document text
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075f1e1edccb---59276193143.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/3vuEKuznOb8/uplcv?utm_term=gluckstein+bed+sheetsPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dbc7.bin
83ac616e975cd6963c1cfa7acb782d8a2ac7fd81c86459a21561bb9e7ea38786
pdf-font-stream PDF embedded font (sfnt) at offset 0xDBC7 4956 bytes
font_01_sfnt_off0000eca4.bin
95848b30ad3e24dce54f4b35befdace61912a0d6991c4711b94789b55ceb4015
pdf-font-stream PDF embedded font (sfnt) at offset 0xECA4 10132 bytes