Malicious PDF — malware analysis report

Static analysis result for SHA-256 089b7ad9e9a0d083…

MALICIOUS

PDF

82.2 KB Created: 2021-03-23 06:31:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-07
MD5: c2ffee924980cd3a622a7b94393f973b SHA-1: 53192ff08267dd36d450ec57e7569243ce2e6e5e SHA-256: 089b7ad9e9a0d083ea6928ccc83b1ee23d0fe6b369ebdc511048e8676aab584f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains embedded URLs pointing to external resources, suggesting it may be used to redirect users to phishing sites or download further malicious content. No scripts were extracted, but the presence of external URLs and the overall detection profile strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=polynomial+inequalities+examples PDF link annotation
    • https://cdn.sqhk.co/tikikizeveni/hew2gcq/south_portland_me_bowling_alley.pdfIn PDF document text
    • http://konolux.medianewsonline.com/83812890122.pdfIn PDF document text
    • https://cdn.sqhk.co/wigatozaduw/0yiaQJB/41972231193.pdfIn PDF document text
    • https://cdn.sqhk.co/kegufamop/cO7iggd/52186174853.pdfIn PDF document text
    • https://cdn.sqhk.co/mapelimujeku/fieXwge/kuzilek.pdfIn PDF document text
    • https://cdn.sqhk.co/sudidoxa/iehesoa/download_game_drive_ahead_mod.pdfIn PDF document text
    • https://cdn.sqhk.co/dopuzodopuvu/njegdPO/75522688435.pdfIn PDF document text
    • https://cdn.sqhk.co/fuzokikili/U58VauD/survivalcraft_2_mod_apk_free_download.pdfIn PDF document text
    • https://cdn.sqhk.co/bagadogod/3kidjdq/6614067996.pdfIn PDF document text
    • https://cdn.sqhk.co/nogorodizet/D4Jgjeu/44061125798.pdfIn PDF document text
    • https://cdn.sqhk.co/xobitabab/igMhchb/99850179369.pdfIn PDF document text
    • https://cdn.sqhk.co/zisujidixa/bRgfih0/54551082454.pdfIn PDF document text
    • https://cdn.sqhk.co/gisepavuv/dshjjjy/44413996596.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/48b46378-42d8-4b42-bc5a-c5dafb4a7f99/the_crucible_act_1_analysis_activity.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e843b90b-b772-4ca4-b3cf-941bb5fc3105/76477787216.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e6659891-e741-4354-8377-3ed9faa1ec89/32270829765.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/054d8466-f947-4cba-9461-4ff9595309de/pexag.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/60eb47d5-122a-446d-aa9e-e9d95ef8b370/81101026316.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d73e748c-cbb8-45ea-93bc-99a6a368be02/watchmen_by_alan_moore_and_dave_gibbons.pdfIn PDF document text
    • http://rigidafavubo.myartsonline.com/80767329059.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e9662a55-2c4a-4908-920f-d94b01511beb/beretikadobo.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed81.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED81 5168 bytes
SHA-256: a661aa40c41c9dd7173e180ce3ee1d273612eef856dca4478259b3a63afeefb6
font_01_sfnt_off0000ff13.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF13 11176 bytes
SHA-256: ffdea28e69b6ff62b484293fb6c40b1770c9f60c9be3cd0a78c5f734d9101910
font_02_sfnt_off000125bc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x125BC 16208 bytes
SHA-256: be46e54c5b3514c579ab84833d7f53aa433e865a7c2fc94b2d3ac26532f02221