Malicious PDF — malware analysis report

Static analysis result for SHA-256 177c5cf0713be604…

MALICIOUS

PDF

153.9 KB Created: 2020-12-25 15:03:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 03e80b3ee77bf7bf6c14635436a3ec31 SHA-1: e804b12197144d33a17cdd4c4b91ffbd5a4b2987 SHA-256: 177c5cf0713be604b44d46580b05c84b794c0ad2719d8557ef197a4728ba01e3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The embedded URL points to a suspicious domain, suggesting a phishing or malware distribution attempt. While no scripts were explicitly extracted, the PDF structure and embedded URI heuristic indicate the presence of malicious content designed to redirect the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/123?utm_term=queen%2527s+blade+ova+5+cattleya+eng
    • https://cdn-cms.f-static.net/uploads/4370778/normal_5fb9785b8f898.pdf
    • https://cdn.sqhk.co/gujadozede/d2jfSgg/bob_the_robber_4_hacked_arcadeprehacks.pdf
    • https://cdn.sqhk.co/dakuwuwuzije/egchhi0/61972956667.pdf
    • https://static.s123-cdn-static.com/uploads/4402014/normal_5fde52ef1a5c5.pdf
    • https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/rujubawafezepir-juvewipapa-misimova-zavizixi.pdf
    • https://static.s123-cdn-static.com/uploads/4417207/normal_5fe1047cf1085.pdf
    • https://fezemopozopedet.weebly.com/uploads/1/3/5/3/135326879/kubawosa_wivupikamo.pdf
    • https://cdn-cms.f-static.net/uploads/4365659/normal_5f86f656c66f7.pdf
    • https://cdn-cms.f-static.net/uploads/4424376/normal_5f9d79d37616f.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/bugutaj/academic_vocabulary_in_use_edition_with_answers_2nd_edition.pdf
    • https://s3.amazonaws.com/bezutu/6123204575.pdf
    • https://s3.amazonaws.com/wutogugej/china_authentication_application_form.pdf
    • https://s3.amazonaws.com/babuxufarizuxur/fast_learner_synonym.pdf
    • https://s3.amazonaws.com/fosawef/stoker_hd_movie.pdf
    • https://s3.amazonaws.com/wibadinavosunom/la_times_crossword_answers_9_4_19.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00016db1.bin
e2c52cefe5f3dae3361ab717277a9afe64b660c7b8f2ea6ec123f3e79d80e2cc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x16DB1 59592 bytes
font_01_sfnt_off000220b3.bin
91e8a7833ae0ff3ca96d93fba8752b1501e5dcb1746d02fa4b36594a48c287e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x220B3 5532 bytes
font_02_sfnt_off000233b6.bin
0e7447a663710395547b4c2bcf7b94dfe09479eb5f07d43c40c43037ee7d7555
pdf-font-stream PDF embedded font (sfnt) at offset 0x233B6 11496 bytes