Malicious PDF — malware analysis report

Static analysis result for SHA-256 1395233af28f9234…

MALICIOUS

PDF

88.2 KB Created: 2021-03-24 12:11:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8229ae509dd7fec7a66f6452f3b34102 SHA-1: dd1ff010be8250260998961867d820f9a84fe966 SHA-256: 1395233af28f9234d2ede805997d0a92b8080a590a3b8048a70c28c185d23add
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an external URI pointing to a URL that appears to be a phishing lure, disguised as a book download. The ML classifier and ClamAV detection strongly indicate maliciousness. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it's designed to trick users into downloading further malicious content, likely through a social engineering pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/award?keyword=applied+physics+book+for+polytechnic+pdf
    • http://inostrana.com/how_to_charge_gibson_g_force_batterybrema.pdf
    • http://zoomita.fun/pycharm_cheat_sheet_mac59fou.pdf
    • http://euroshopmn.space/apc_back-ups_500va_battery_replacementi3cp2.pdf
    • https://cdn.sqhk.co/xovatagemi/5lzlhfU/tetimivu.pdf
    • https://cdn.sqhk.co/terisuzuji/agjjija/jusirigusawofesuliki.pdf
    • http://meetchat.space/tuvirasarub1lcm.pdf
    • https://cdn.sqhk.co/guposidum/hiJPVhd/34322798141.pdf
    • http://kieverts.xyz/41962138110bs47u.pdf
    • http://vuvuga.xyz/lixegizd1htj.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/44022d4c-5b2f-491a-b520-ba08b59079e6/30941955160.pdf
    • http://tegewixu.epizy.com/sharepoint_2013_designer_workflow_end_of_life.pdf
    • https://uploads.strikinglycdn.com/files/8caa2be6-39b9-4ebb-a9a4-679a56cac0d4/narusaborogoxuvefabal.pdf
    • https://uploads.strikinglycdn.com/files/df304c3b-41eb-4c50-9c4a-7b865add192e/kepodukazodudakaturer.pdf
    • https://uploads.strikinglycdn.com/files/66454969-b0c5-4490-a7c8-d45224f82dbb/53736585067.pdf
    • https://uploads.strikinglycdn.com/files/bfa86cd0-f44a-4343-b0dc-f918a6beedeb/how_to_decipher_gravity_falls_journal_3.pdf
    • https://uploads.strikinglycdn.com/files/0ddb8726-521d-4401-8734-19e4967ea402/escape_from_mr._lemoncellos_library_cast.pdf
    • http://wejifofodig.rf.gd/87705598198.pdf
    • https://uploads.strikinglycdn.com/files/2caf9cd8-7d8e-4251-98e8-57cc867588d6/14252924277.pdf
    • https://uploads.strikinglycdn.com/files/ae30d112-9b34-4231-8628-a2c80549beb2/thetford_rv_toilet_valve.pdf
    • https://uploads.strikinglycdn.com/files/e4f4349b-be42-43fa-a2e3-1ac3a87aa26f/definition_of_a_rumble_fish.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010d21.bin
80b019e740c617a3c72c6e1e249d130d3579622b7f62dfb3e57c5f2657380a36
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D21 5328 bytes
font_01_sfnt_off00011f43.bin
2b2aa27ff9f8afca526fa4875e32a66fe409afb8c64fb7f444f2e82e68a611ab
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F43 16652 bytes