Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d8ced45f77bab49…

MALICIOUS

PDF

122.7 KB Created: 2021-04-05 21:49:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bdf3c8ed56b234c4a2855fb90d508cf7 SHA-1: d05a57732a6848e70cd15f1374856ec21ebe387a SHA-256: 0d8ced45f77bab498a8086ead93cd4cb43cf444c3d1f20ea950110e843246e17
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL pointing to a suspicious domain, likely intended to redirect the user to a malicious site. The document body, though heavily obfuscated, suggests a lure related to 'chemistry solutions review answer key', aligning with a phishing or scam attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=chemistry+solutions+review+answer+key
    • https://guvijubeb.weebly.com/uploads/1/3/5/3/135318684/f3f77.pdf
    • http://goromeo.club/windows_xp_bootable_usb_iso8vafr.pdf
    • http://vengriya.space/sujelipaxeribawite2jzg.pdf
    • http://kungfumalibu.com/pelimitabojujulipunagutikfv7e.pdf
    • http://reduslim-eu.site/what_is_a_candid_shot_in_photography4ro8h.pdf
    • https://vidajubobulixi.weebly.com/uploads/1/3/4/6/134650234/bejoloje.pdf
    • http://justiciaforjustice.com/86194443084mh30m.pdf
    • http://idealslimitaly-official.site/80971412932aj46y.pdf
    • https://vafebukuwu.weebly.com/uploads/1/3/1/1/131163563/mopixaxurifo.pdf
    • https://tekoxinir.weebly.com/uploads/1/3/4/6/134606092/deledumajirisaki.pdf
    • http://kulinar2020.site/georgia_driving_school_practice_testdcqyh.pdf
    • http://detonic-italia.website/519660933161qgc.pdf
    • http://eslife.pro/acer_laptop_power_cord_replacementwyymh.pdf
    • http://tameeniraq.com/eso_shiny_dyes8w8b1.pdf
    • https://buvonage.weebly.com/uploads/1/3/0/9/130969236/vazon.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://gizoronof.epizy.com/is_the_southwest_rapid_rewards_priority_card_worth_it.pdf
    • http://zoxalojidud.epizy.com/farberware_single_serve_k-cup_brew_coffee_maker_manual.pdf
    • https://s3.amazonaws.com/wenobagupexekap/girl_dress_up_games_for_mobile.pdf
    • http://finemadajurene.epizy.com/czasy_przesze_angielski_cwiczenia.pdf
    • https://s3.amazonaws.com/tetofamuxulil/62802446158.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018ecc.bin
5eb3cce06c2046819dec8d71368f086baaf69bf52b36819ddcf045f99a359e6e
pdf-font-stream PDF embedded font (sfnt) at offset 0x18ECC 5148 bytes
font_01_sfnt_off0001a02e.bin
2d4d82f9e953925c6b7d23674bcc1e152eb9f2a141a7c8dacb210d5516c13037
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A02E 11808 bytes
font_02_sfnt_off0001c8ad.bin
2d958bd008b8db5b33092f112e99c856adbcc0a100e950d14ff814b784be6357
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C8AD 16060 bytes