Malicious PDF — malware analysis report

Static analysis result for SHA-256 14a1e655c83ee2b5…

MALICIOUS

PDF

88.7 KB Created: 2021-05-10 22:11:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 48d4fdce70e569f367525599da607b74 SHA-1: 8009f063fb92d72b57229b921f3fff4900a9ccbd SHA-256: 14a1e655c83ee2b548714683f131e7ab3aa7551bea546e605629598250d7b8fa
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document identified as malicious by ClamAV and an ML classifier. It contains embedded URLs and heuristics indicate the presence of a download button lure. The document body, though heavily obfuscated, suggests a theme related to downloading content, likely a pretext for a phishing or malware delivery attempt. No scripts were extracted, but the presence of external URIs points to a potential download or redirection mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9951

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=the+maze+runner+2+dual+audio+hindi+480p+bluray+free+download
    • https://cdn-cms.f-static.net/uploads/4382627/normal_6024a87128a7b.pdf
    • https://static.s123-cdn-static.com/uploads/4407302/normal_5fe5a237b2686.pdf
    • http://musc-media.xyz/technical_english_1_course_book_answersxikik.pdf
    • http://gufutaca3.xyz/353150990073r6qp.pdf
    • http://alluniversity.fun/inama_challenge_mp4dfquv.pdf
    • http://nomevufaneboja.mypressonline.com/nixixivenidibufexare.pdf
    • https://static.s123-cdn-static.com/uploads/4450636/normal_5fe52f7373227.pdf
    • https://cdn-cms.f-static.net/uploads/4413566/normal_6066ef076e9c1.pdf
    • http://goligofalu.medianewsonline.com/gejek.pdf
    • https://static.s123-cdn-static.com/uploads/4403260/normal_600573a12b98e.pdf
    • http://torchland.xyz/lunuwezas8d1we.pdf
    • http://keksik24.ru/46874374585o27zl.pdf
    • http://fanutoragozogow.sportsontheweb.net/what_causes_a_dishwasher_to_not_clean_well.pdf
    • http://proita.fun/how_to_write_hundredths_as_a_decimaliw14c.pdf
    • http://lowwsaw.xyz/how_to_use_a_bissell_pet_3_carpet_cleanerhxo64.pdf
    • http://iranianvc.com/54014816863m66y4.pdf
    • http://casser.xyz/8406586473vlxnp.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/bb23eb47-63b3-47ef-b626-d7a266c5d356/52939572535.pdf
    • https://s3.amazonaws.com/pavujiniz/fezomadar.pdf
    • https://s3.amazonaws.com/pugomonapoxuxe/21241122862.pdf
    • https://uploads.strikinglycdn.com/files/1286086e-df94-4cfa-a3c7-1428f90258a4/luzudatixal.pdf
    • https://s3.amazonaws.com/muvazi/arabic_grammar_book_in_bangla.pdf
    • http://kagijido.myartsonline.com/94533994917.pdf
    • https://uploads.strikinglycdn.com/files/0cf657d7-245b-47cf-9879-7e20ff4a6cd1/81724272609.pdf
    • http://salajire.onlinewebshop.net/moladarapaxakuselexane.pdf
    • https://uploads.strikinglycdn.com/files/c1544bde-fc65-43a5-839c-6c0986fa5f1a/95347810587.pdf
    • https://uploads.strikinglycdn.com/files/051d9dcb-97d1-4687-8145-60407b8d776d/xidapaxobilemujanig.pdf
    • https://s3.amazonaws.com/wiwuxot/behen_hogi_teri_movie_full_song.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001076c.bin
27bf55d1e0e9ef1d9e3bbfa0d40ae2a7a5188761d7de2d4f711db1c088df8341
pdf-font-stream PDF embedded font (sfnt) at offset 0x1076C 5796 bytes
font_01_sfnt_off00011b04.bin
0c092a75847b8dfdd641694983551a3cd89c84bf415e39a1761665a9a09f76fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x11B04 13488 bytes
font_02_sfnt_off0001460c.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1460C 4324 bytes