Malicious PDF — malware analysis report

Static analysis result for SHA-256 13a60e381edbf799…

MALICIOUS

PDF

71.1 KB Created: 2021-02-17 17:09:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 487cbb33589ad6b6d2eadc2267e1834e SHA-1: af98df25317596d15807e087aa1030575e5d651c SHA-256: 13a60e381edbf799b827e2183bf8ebcfaaa646c3746a52bb9c398c758f7211ee
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/strik?utm_term=how+to+set+up+voicemail+on+my+landline+phone PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4410678/normal_602c760732996.pdfIn PDF document text
    • http://anstel.pro/hotel_casinalbo_di_formigineuhzc0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4420905/normal_5fe487447b552.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4416301/normal_5fd805f58420b.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4366620/normal_5ff06b50d0496.pdfIn PDF document text
    • http://meetchat.space/juwolelibunurif4ha.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4501042/normal_5fcecba711071.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4377109/normal_602a28d5daaad.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4454424/normal_60051f3228115.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475376/normal_601cff531f9c9.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403410/normal_5fe5dfee69247.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4450632/normal_5fe5f2c2ba459.pdfIn PDF document text
    • http://health2health.online/wukabiwigwkbcu.pdfIn PDF document text
    • http://inostrana.com/903426887614b7rw.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://latowetutut.epizy.com/two_variable_linear_equations_worksheet.pdfIn PDF document text
    • https://s3.amazonaws.com/kopisigapub/bahut_pachtaoge_new_song.pdfIn PDF document text
    • http://jukigegamoma.epizy.com/53793776687.pdfIn PDF document text
    • http://fofifalog.rf.gd/droidadmin_for_android_box.pdfIn PDF document text
    • https://s3.amazonaws.com/juzinaramip/affidavit_template_queensland_magistrates_court.pdfIn PDF document text
    • http://sekovukubetib.epizy.com/mk11_fatality_guide_ps4.pdfIn PDF document text
    • http://tatifamajerub.epizy.com/rupijofubenodaxixenafil.pdfIn PDF document text
    • https://s3.amazonaws.com/zuvovoxigumuz/gisider.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d8af.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD8AF 5432 bytes
SHA-256: cec01c770292da2469ba96ce63321ae0504d8d0875d82719b133c291b432eb41
font_01_sfnt_off0000eb1f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB1F 10304 bytes
SHA-256: dc7bda47ad1c1720e19a9549d2756201a23c9cf8b1e78f5567f74ee7df75af60