Malicious PDF — malware analysis report

Static analysis result for SHA-256 111d21058e7ac04c…

MALICIOUS

PDF

71.1 KB Created: 2021-05-03 23:37:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 828fe98db7870bcba803a5adeccd931f SHA-1: 681286a033c7ca95797b1436061630e2bfd9bbd3 SHA-256: 111d21058e7ac04c89dd4a5de1aa327e56e252e75e004620587ff6d6b7f5dcd1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. Embedded URLs suggest a phishing or malware distribution attempt, likely delivered as a spearphishing attachment. No scripts were extracted, limiting the analysis of specific execution behaviors.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.louthadventures.ie/wp-content/plugins/formcraft/file-upload/server/content/files/1608718b64c86c---77902468478.pdf
    • https://www.auditek.fr/wp-content/plugins/formcraft/file-upload/server/content/files/1606f08a065db8---48980852971.pdf
    • https://autoschiller.de/wp-content/plugins/formcraft/file-upload/server/content/files/16077b5528e260---21107280665.pdf
    • https://too.kg/wp-content/plugins/super-forms/uploads/php/files/0eb9db8476a75163f58fc117d5da2cb7/bufagavuzozelejapufejugi.pdf
    • https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/sfm1flj65kuk96p3g84jvj18ed/35960829934.pdf
    • https://qualitylightsolutions.com/wp-content/plugins/super-forms/uploads/php/files/459de13afb8cbf0424d643df3a8398d4/mukure.pdf
    • https://www.ideaklinikankara.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074c67eace75---43712038089.pdf
    • http://www.guaitoli.eng.br/wp-content/plugins/formcraft/file-upload/server/content/files/160703f78c813a---74666836500.pdf
    • http://animalscipublisher.com/files/upfiles/file/6977815018.pdf
    • https://luxmarketing.agency/wp-content/plugins/super-forms/uploads/php/files/4nukbg3fe58rh060dr1b4b4h9p/xabibujuw.pdf
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160722bb344d0c---7977034522.pdf
    • http://www.deadclan.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16072335f75da3---18572859869.pdf
    • https://www.isnb.co.uk/wp-content/plugins/super-forms/uploads/php/files/e1e4db11339997bd64daa2f007c23edc/90988547717.pdf
    • https://www.swx.global/wp-content/plugins/super-forms/uploads/php/files/87c2be63768e094acbc3a203c7aaaea7/zigixanevara.pdf
    • https://c4ir.ae/wp-content/plugins/super-forms/uploads/php/files/skh0cephf4492hkkf17a15opd5/kovoke.pdf
    • https://www.lightingdynamics.com/wp-content/plugins/super-forms/uploads/php/files/e494886724967856a11157c619caa941/93856451006.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/skout/mBVl/~3/BkSY9tpko7c/uplcv?utm_term=bad+boy+image++hd
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000daf5.bin
29d7b7e2516dce387d3dc639e9ccb882a81874cc8adbdcd2ee10988535ed4ae9
pdf-font-stream PDF embedded font (sfnt) at offset 0xDAF5 5224 bytes
font_01_sfnt_off0000eca1.bin
e61670344ee795513a60cd0c6b64a4f0db1c51e1f34e6156b3f639d378a68708
pdf-font-stream PDF embedded font (sfnt) at offset 0xECA1 10340 bytes