Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a7efbcdd191e2b8…

MALICIOUS

PDF

87.9 KB Created: 2021-03-28 23:15:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9893dfca0d36d065def4ed9b8752acc0 SHA-1: b208618f8bdf73b1e5a3697c2d96ee930efad957 SHA-256: 0a7efbcdd191e2b82a6f5bb6b79615ea4899d1245dc6be88136c89cb981ce738
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI that directs the user to a URL, likely to download a second-stage payload. The ML classifier and ClamAV detection strongly indicate malicious intent, consistent with a phishing lure for a document download. No scripts were extracted, but the presence of external URIs and the overall detection profile suggest a typical phishing or malware distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=springboard+geometry+page+2
    • http://lujadexezusunam.22web.org/nixiduro.pdf
    • http://fiwirumoded.22web.org/45387345715.pdf
    • https://cdn.sqhk.co/vutowogipu/YjfCWib/download_block_tank_wars_mod_apk.pdf
    • http://xatakafigudu.getenjoyment.net/70832753203.pdf
    • https://cdn.sqhk.co/tijaxasazuwi/Hgiiagf/weather_liverpool_uk_met_office.pdf
    • http://bajifepeselok.sportsontheweb.net/reduce_file_size_below_100_kb_online_free.pdf
    • https://banafazag.weebly.com/uploads/1/3/4/3/134325205/lukejoxama_fonawi_xiwajut.pdf
    • https://cdn.sqhk.co/tofigidukug/adi3QYw/gibbets_bow_master_mod_apk_hack.pdf
    • https://cdn.sqhk.co/togodawexu/VkC6jiZ/28788630510.pdf
    • http://vatirigidofaxu.iblogger.org/delofig.pdf
    • http://raxewapikeb.mygamesonline.org/56923724055.pdf
    • http://radanukodufam.22web.org/catalizadores_homogeneos.pdf
    • https://bijafifevidajun.weebly.com/uploads/1/3/6/0/136051066/2921406.pdf
    • https://zawasofolebu.weebly.com/uploads/1/3/4/9/134902788/tidusabi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fipaliwabalutu.rf.gd/employee_bonus_program_guidelines.pdf
    • http://jisijuvod.myartsonline.com/mental_status_examination_form_free_download.pdf
    • http://wekujugom.epizy.com/spoken_english_book_for_beginners.pdf
    • http://nujuvidiramefo.epizy.com/burajoxit.pdf
    • http://jadigilotuziwir.rf.gd/zodus.pdf
    • http://wonanikapudidak.atwebpages.com/weekly_meal_planner_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb1f.bin
aff8a5171ebd555e6109bb898614a21620bfbb061e44e46ea888f7a6e10e3ad1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB1F 5544 bytes
font_01_sfnt_off00010de8.bin
ccb43d6d02ef99528671394b0f4b95e42c29d3145ac1e0718b562816eaf9d967
pdf-font-stream PDF embedded font (sfnt) at offset 0x10DE8 14564 bytes
font_02_sfnt_off00013b8b.bin
10c3134811a9f18c496b90a04dfb4d02f3b5bcc88c6298ae91119f541caf8668
pdf-font-stream PDF embedded font (sfnt) at offset 0x13B8B 16120 bytes