Malicious PDF — malware analysis report

Static analysis result for SHA-256 0911e7f36bd2f242…

MALICIOUS

PDF

86.4 KB Created: 2021-03-25 06:57:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 46b92abbcdc924686f5bc499ee842836 SHA-1: 2cb54819f838b973676d3a8ba1937019317d1903 SHA-256: 0911e7f36bd2f242b094c624efebae833bf0c66d1078d9c2948b6e17fd6dc792
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, and ClamAV detection confirms its malicious nature. The ML classifier also strongly flagged this PDF as malicious. The document body is heavily obfuscated, but the presence of external URIs suggests an attempt to redirect the user to a malicious site, likely for phishing or to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/wix?keyword=greyhawk+calendar+pdf
    • http://premium-cinema.com/persepolis_graphic_novel_read_onlinezxu4j.pdf
    • http://vereffka.xyz/pelicula_completa_de_amor_y_otras_adicciones_en_espaolv568s.pdf
    • http://titanovyi-filtr.ru/oxford_dictionary_of_english_app_storeez3c1.pdf
    • https://static.s123-cdn-static.com/uploads/4468289/normal_5fdf98e939358.pdf
    • http://gobigs.space/diwosepokhepw.pdf
    • http://static-get.top/word_game_app_2_player4as66.pdf
    • https://cdn-cms.f-static.net/uploads/4408720/normal_60599018b0bcd.pdf
    • http://paruvam.22web.org/kodifexabilukaposunasit.pdf
    • http://mkr-olimp.info/anarchist_cookbook_original_1971_ebay6pn0z.pdf
    • https://cdn-cms.f-static.net/uploads/4416919/normal_601aae365aaec.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://juxuvirorut.epizy.com/57294010403.pdf
    • https://s3.amazonaws.com/vixuwogetiv/bad_boy_lyrics_saaho_telugu.pdf
    • https://s3.amazonaws.com/lurutopobi/polar_ft60_battery.pdf
    • https://s3.amazonaws.com/fekazudabo/biblia_griega_en_espaol.pdf
    • https://s3.amazonaws.com/jivamubug/99085455595.pdf
    • http://lesexuxu.rf.gd/brandy_bottle_image_free.pdf
    • https://s3.amazonaws.com/kezemiradigu/58367508342.pdf
    • https://s3.amazonaws.com/guwutivupudutu/tezugofemibuxo.pdf
    • http://naratide.epizy.com/7339372973.pdf
    • https://s3.amazonaws.com/dotivaf/iceberg_slim_pimp_audiobook.pdf
    • https://s3.amazonaws.com/vukumesoj/cecil_county_dragway_sheets.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001156a.bin
a7374ca89aae791dcef5a09fc3b34e6be32eb044a7a9a378be4caed820965fd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x1156A 5352 bytes
font_01_sfnt_off000127b9.bin
3c674482ccc2639fefbcdba626884a33d27c52b5443633c39b269666e5f836d6
pdf-font-stream PDF embedded font (sfnt) at offset 0x127B9 10828 bytes