Malicious PDF — malware analysis report

Static analysis result for SHA-256 0eb34dc0efde4ec2…

MALICIOUS

PDF

74.6 KB Created: 2021-03-28 05:58:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a5760cd7201a3cccbe52597164088e49 SHA-1: 2003b5fdc1907b01b36f8190c5995601564ada50 SHA-256: 0eb34dc0efde4ec262ee6a1d636bcf6b6becefc6df1fd75a10e0a8528568b3c8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded URLs, with one specifically matching a search query for 'Breckinridge county schools hardinsburg ky', suggesting a phishing or social engineering lure. ClamAV detection and ML classification strongly indicate malicious intent, likely related to phishing or trojan delivery. The presence of an external URI points to the download of a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=breckinridge+county+schools+hardinsburg+ky
    • https://cdn.sqhk.co/jupemuwaze/2rwjeji/53634106510.pdf
    • https://cdn.sqhk.co/xuxawexa/iijhKcG/nomokisetuleropatenowa.pdf
    • https://cdn.sqhk.co/puxedepobe/1g6gil7/1820464323.pdf
    • https://cdn.sqhk.co/kekelivig/DXjbCAs/peruwidugituboluvevujasuw.pdf
    • https://cdn.sqhk.co/tejurorado/eVjgrhj/53400203570.pdf
    • https://cdn.sqhk.co/tinolaseja/aVQjjii/learn_to_speak_spanish_free_audio_books.pdf
    • http://djami.ru/birches_poem_analysisgyg0d.pdf
    • http://kurewegunopef.66ghz.com/wuzawikivabuvivaripod.pdf
    • https://cdn.sqhk.co/mugolino/agjzgcS/engineering_graphics_essentials_answer_key.pdf
    • https://cdn.sqhk.co/jamolipa/R9giBtg/jizefiwokerodi.pdf
    • http://boost-store.net/shipwrecked_kauai_instagram3f9v2.pdf
    • https://cdn.sqhk.co/sanojuxako/hECnage/word_crossy_cheats_level_908.pdf
    • https://cdn.sqhk.co/gejupajo/cpge7ja/purewabu.pdf
    • http://verunej.iblogger.org/fufupibesudemaze.pdf
    • https://cdn.sqhk.co/fazofasufiwu/u7Tibhj/80187467637.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/wefadep/fractions_decimals_and_percentages_ks2_worksheet.pdf
    • https://s3.amazonaws.com/pujirageg/mopewopixewonusonawitivo.pdf
    • http://bireses.rf.gd/aplikasi_canva_pro_mod_apk.pdf
    • http://xemugapot.rf.gd/how_do_i_troubleshoot_my_kenmore_dryer.pdf
    • https://s3.amazonaws.com/wuxupewu/assam_map_image.pdf
    • https://s3.amazonaws.com/mizeteb/como_descargar_la_biblia_catolica_latinoamericana_en_audio.pdf
    • https://s3.amazonaws.com/levumoduf/character_design_book_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3ed.bin
fc466a7e60c9973d1725f1b1e1dbaa4457b4b0aec540c00df3e867ce97dd0256
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3ED 5556 bytes
font_01_sfnt_off0000f6d8.bin
211aae275a52c4e634c891c128fdf9066a6000652237ee521ee9b3d903c8d7a5
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6D8 11352 bytes