Malicious PDF — malware analysis report

Static analysis result for SHA-256 13d4ed7007ceadfe…

MALICIOUS

PDF

63.2 KB Created: 2021-01-17 08:05:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-05
MD5: 85ddf1758e9b4c7c49545df0d58b8279 SHA-1: efd478a49ce4fb273fe5e5f933b873a64ae4cfaf SHA-256: 13d4ed7007ceadfe2eb2add59b1f658dbe34f81a25a958ba83726e1f1eced3c1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The embedded URL points to a suspicious domain, likely serving as a lure for users interested in 'unblocked games hockey legends'. While no scripts were explicitly extracted, the PDF structure and the presence of external URIs suggest it's designed to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/123?utm_term=unblocked+games+hockey+legends PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4409619/normal_5fbb646e055a8.pdfIn PDF document text
    • https://milafesubori.weebly.com/uploads/1/3/4/7/134745217/6078374.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4384145/normal_5ffd58876b5d7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4476938/normal_5fe6265e19e15.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4489733/normal_5faaa670426ce.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4414169/normal_5fc44605d337d.pdfIn PDF document text
    • https://cdn.sqhk.co/xubupigegi/cjcRnjh/tokezekelubutozajafome.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/tofizo/47068444741.pdfIn PDF document text
    • https://s3.amazonaws.com/baxegezivumi/essay_writing_guidelines.pdfIn PDF document text
    • https://s3.amazonaws.com/vetamedisoz/nedusozul.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b9f8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB9F8 5552 bytes
SHA-256: 165ba16b84dac96feff26ac202bd921ee3ce82793e7c9a0debd49f0194fd20cc
font_01_sfnt_off0000ccbf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCCBF 10392 bytes
SHA-256: 27be6ee122b5bbfc789b9ba13f6ab4d180b2cb088c6aedd848a5f41959042814