Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a55fe407874b383…

MALICIOUS

PDF

79.5 KB Created: 2021-03-30 05:44:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1d2702b8fb566c48038c4b46fd0944d8 SHA-1: bb965868f3544bab6d6571361491a7c2821f0aec SHA-256: 0a55fe407874b3832a691ec28edaed88aed79bb588ca4f51f0cce119e392e0e7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains multiple embedded URLs, with one specifically referencing a "wmf pressure cooker manual" to deceive the user. ClamAV and ML classifiers strongly indicate maliciousness, consistent with phishing or malware distribution. The presence of external URIs suggests an attempt to download further malicious content or redirect the user to a phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=wmf+pressure+cooker+manual
    • http://rejemezurufoveg.mywebcommunity.org/cbse_6th_class_maths_textbook_solutions_in_hindi.pdf
    • https://cdn.sqhk.co/jarogofef/fjdMFjh/44694476824.pdf
    • https://mawurimi.weebly.com/uploads/1/3/4/6/134661678/xetepolibazapazobas.pdf
    • http://lixidepobejoji.mypressonline.com/e4_evaluation_form.pdf
    • http://thefortykuti.com/warframe_beginner_guidenl0x0.pdf
    • http://tomandbxof.site/97629318625lfdmz.pdf
    • http://agentsoft.space/bajrangi_bhaijaan_songs_free_pkjizwr.pdf
    • https://cdn.sqhk.co/tasokuxu/jhhhhif/77915449451.pdf
    • https://cdn.sqhk.co/wetotuluxe/jfshhgj/growth_mindset_worksheets_for_elementary.pdf
    • https://cdn.sqhk.co/xokebuzizo/hdhgljh/radioactive_dating_game_activity_answer_key.pdf
    • http://smartbright.club/oxford_student_atlas_for_india_2nd_editionz7oob.pdf
    • https://cdn.sqhk.co/fimegasaz/haZRgZd/35266636299.pdf
    • http://stroy-level.ru/84975499420bay2.pdf
    • http://milansit.space/degexetoza2ukn.pdf
    • https://geguxawuxereko.weebly.com/uploads/1/3/1/3/131379712/viwulexifijenunulolo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/wixatax/kemavevux.pdf
    • https://s3.amazonaws.com/fukepez/zilowamigovobekezubuf.pdf
    • http://lurarapekakaka.atwebpages.com/pdf_oscilloscope_tutorial.pdf
    • https://s3.amazonaws.com/lorifawuvawot/capital_of_indian_states_in_tamil.pdf
    • https://s3.amazonaws.com/kimone/walmart_photo_promo_code_prints.pdf
    • https://s3.amazonaws.com/saxefi/wuzenirozedajurazake.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f9de.bin
6b5a91edea14c3c07e8388f41439fc93eff72dee6b312bf4de014ed7a9bfcc63
pdf-font-stream PDF embedded font (sfnt) at offset 0xF9DE 5236 bytes
font_01_sfnt_off00010bb0.bin
d622a25b3b80cb0b43a352bd70613af85dd04fc7172081d9791901ce1896a8dc
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BB0 11020 bytes