Malicious PDF — malware analysis report

Static analysis result for SHA-256 1721a994ea41f033…

MALICIOUS

PDF

75.9 KB Created: 2021-04-08 17:45:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9f7d6142661ea218d14aa048805e0b09 SHA-1: 7551a2a21e4e0ec57444b7418d07f3f91f4b9418 SHA-256: 1721a994ea41f033e5e7f60edcb4505d0c293db13d60630ae97a3c45773fc553
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to a suspicious domain, which is likely intended to redirect the user to a phishing or malware distribution site. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, and the presence of embedded font streams is common in malicious PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=camilo+y+evaluna+boda
    • http://tumbaa.space/walumaxuxomosalunusawasugw4uw.pdf
    • https://cdn.sqhk.co/dogutadova/dgghgeu/extreme_car_simulator_2016_androidoyunclup.pdf
    • https://cdn-cms.f-static.net/uploads/4371543/normal_6056f885f04cd.pdf
    • https://cdn.sqhk.co/xamitarerivu/dhdgeii/stay_alive_board_game_commercial.pdf
    • https://cdn.sqhk.co/gadewekunel/juieohj/kefavise.pdf
    • http://relax35.ru/riverside_golf_range_nottinghampmlkt.pdf
    • https://static.s123-cdn-static.com/uploads/4384464/normal_6002c66756c2d.pdf
    • https://cdn.sqhk.co/nemuvefik/inj4zDK/titalefujadigurit.pdf
    • http://wajazenizur.mywebcommunity.org/dmv_learners_permit_book_dc.pdf
    • https://static.s123-cdn-static.com/uploads/4419820/normal_6003e2bfc2766.pdf
    • https://cdn-cms.f-static.net/uploads/4475000/normal_601f110f1ee0a.pdf
    • https://cdn.sqhk.co/sixitigoxeto/qhbWc5w/35783508051.pdf
    • https://cdn.sqhk.co/jafetegupam/Mbhjiby/feasibility_study_of_a_systematic_approach_for_discontinuation.pdf
    • http://storeplus.info/poutine_food_wishesrjo29.pdf
    • http://datingsexchat.site/jotekuxeumsgo.pdf
    • https://cdn.sqhk.co/sawibevas/wBifus9/zombie_invasion_escape_walkthrough.pdf
    • https://cdn.sqhk.co/kudozaporuro/aijejfI/fios_tv_pay_online.pdf
    • https://cdn.sqhk.co/lopijikuvi/Sf7FBjg/waragawedowebesefa.pdf
    • http://wildber.store/how_to_remove_ninja_blender_handle9zkxm.pdf
    • https://cdn.sqhk.co/zowipitilo/Paghaar/midas_m32_user_manual.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://nopawalaxuwaw.onlinewebshop.net/ejercicios_present_perfect_still_yet_already.pdf
    • https://s3.amazonaws.com/biwubeleba/95755100452.pdf
    • https://s3.amazonaws.com/suzujewa/37233323801.pdf
    • https://s3.amazonaws.com/palikuvexake/loxowarazunejuf.pdf
    • https://s3.amazonaws.com/timituvupame/xovunizizavedenesavisimo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9c8.bin
61a9e185c7dfa5af87c049b8e6ca8eaff6fa260f6224aab2fc8ac289eaf5d7bf
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9C8 4904 bytes
font_01_sfnt_off0000fa6b.bin
3358bfcc067d8b1bf2b4313e1ed53af7891d0b9ad66d35abed8c96dd7e01049a
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA6B 11560 bytes