Malicious PDF — malware analysis report

Static analysis result for SHA-256 0b95ca70fee516be…

MALICIOUS

PDF

77.2 KB Created: 2021-03-11 19:01:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dfb178a18a2820b5e43f55545370c1ec SHA-1: bf293a789b869e8734ec24de3545ebe973aa42f4 SHA-256: 0b95ca70fee516bea4bc3dff6803891d5fc205dae32f3f9076aef799e2865907
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to redirect users to malicious content, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=bissell+cleanview+vacuum+filters
    • https://static.s123-cdn-static.com/uploads/4378378/normal_5ff7c46b4570f.pdf
    • http://jijuduli.mywebcommunity.org/gobibazudoneweminalorudod.pdf
    • https://cdn-cms.f-static.net/uploads/4380528/normal_604702e333f26.pdf
    • https://cdn-cms.f-static.net/uploads/4492593/normal_603cb95b5b5ec.pdf
    • http://bifokagomasema.iblogger.org/data_structures_and_algorithms_in_c_2nd_edition_solution_manual.pdf
    • http://lofajemami.sportsontheweb.net/55417229747.pdf
    • http://ru-payment.casa/toro_20016_air_filtergut64.pdf
    • https://static.s123-cdn-static.com/uploads/4387716/normal_5feb158156c4a.pdf
    • http://xivitej.66ghz.com/marathi_aarti_sangrah_free.pdf
    • http://tavafotuzefox.sportsontheweb.net/google_maps_not_showing_street_view_iphone.pdf
    • http://swiss-gear.shop/kizinovinixevovazuzribjf.pdf
    • https://static.s123-cdn-static.com/uploads/4453889/normal_5ff55e6ae4e78.pdf
    • http://waxinexedodupij.22web.org/nugifizu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://suvalomimo.atwebpages.com/hp_officejet_pro_8500a_plus_not_printing_color.pdf
    • http://perexuwofogefo.onlinewebshop.net/mezotudokudadazisomewufuv.pdf
    • http://sabukizazuse.epizy.com/nolibunapu.pdf
    • http://kezaforow.epizy.com/chiari_like_malformation_and_syringomyelia.pdf
    • http://jujageritoxo.atwebpages.com/wemo_maker_factory_reset.pdf
    • http://mujedofagogi.epizy.com/32903222262.pdf
    • http://zisukuvi.atwebpages.com/lasejavimoputasi.pdf
    • http://fifaleniw.epizy.com/medawemirupik.pdf
    • http://nutukame.rf.gd/29330085057.pdf
    • http://migusopugaj.epizy.com/28546142263.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f198.bin
9a6044f48cb1331e47cabb8bb752bf8e62fa149d3d9caef16db17257003fddad
pdf-font-stream PDF embedded font (sfnt) at offset 0xF198 5228 bytes
font_01_sfnt_off00010363.bin
7591cc2d99f6a0a8aae61615233c6e3c4c6e8b046d43a74ece51f3345f7c0069
pdf-font-stream PDF embedded font (sfnt) at offset 0x10363 10528 bytes