Malicious PDF — malware analysis report

Static analysis result for SHA-256 0862d95ecdccf297…

MALICIOUS

PDF

195.6 KB Created: 2021-03-04 08:55:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b432ce195adebf340e02e1b845d4d481 SHA-1: 95045147053f31ec4ba15c8748c36305040320bb SHA-256: 0862d95ecdccf2979788e326b85512200dc08e3fb10825158143dd9ade7509cb
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains embedded URLs that point to potentially malicious domains, as indicated by the ML classifier and ClamAV detection. The document body, though heavily obfuscated, suggests a lure related to 'wii u gamepad sensor' to entice users to click on the embedded links. No scripts were extracted, but the presence of external URIs and high confidence malware detection suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=how+to+use+wii+u+gamepad+sensor
    • https://negowuvezesat.weebly.com/uploads/1/3/4/8/134859399/4993729.pdf
    • https://poxesaxe.weebly.com/uploads/1/3/0/7/130738711/rosolutivurekej-bimodi-lorubokagomun.pdf
    • http://mavito.online/factores_de_riesgo_de_la_obesidad_infantilphra6.pdf
    • http://prizinsta.site/mikenobibun1vyn.pdf
    • https://niwosegebopusa.weebly.com/uploads/1/3/4/5/134583118/6526981.pdf
    • http://like-store.site/courageous_leadership_bill_hybels1u1k4.pdf
    • https://pewovorawegoxuv.weebly.com/uploads/1/3/4/3/134351704/5611026.pdf
    • http://dontbeshy.xyz/6396774239itwgj.pdf
    • https://sivekilupikuma.weebly.com/uploads/1/3/4/4/134491743/8495419.pdf
    • https://rodazikajoreme.weebly.com/uploads/1/3/0/8/130874285/6179ee790ac6e.pdf
    • https://mexilaret.weebly.com/uploads/1/3/0/7/130775974/dajoki_fifedanakez_riguposokede.pdf
    • http://winopufivugum.22web.org/98943657205.pdf
    • https://nenuwuxajifop.weebly.com/uploads/1/3/4/6/134665141/buxilixelijit.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://sidepojedava.myartsonline.com/77603131562.pdf
    • http://dokebipozo.epizy.com/do_furnaces_have_reset_buttons.pdf
    • http://mozutulobiris.onlinewebshop.net/66463644951.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00028297.bin
6b7541ca91c94e60ab36081f075d0e1d303874e4503e96c7412fc3645bc23e7f
pdf-font-stream PDF embedded font (sfnt) at offset 0x28297 20168 bytes
font_01_sfnt_off0002c35b.bin
bb3f6b8c26d28f500da9b5ecd520acfaffb2e8478b0501dc52715c72fc4cd941
pdf-font-stream PDF embedded font (sfnt) at offset 0x2C35B 5300 bytes
font_02_sfnt_off0002d55c.bin
d270f04c550619978b0f729372f343efcd73a1f7757e33efca587cd663beda90
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D55C 13084 bytes