Malicious PDF — malware analysis report

Static analysis result for SHA-256 1adbbc8a4afd99b8…

MALICIOUS

PDF

76.3 KB Created: 2021-03-14 06:54:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b1f46fde13f5eba4b2bf964f47ff7a2c SHA-1: 42aba189b681770f7cf81efc0d847e739ed1b7c8 SHA-256: 1adbbc8a4afd99b82df3e42145d27688e051267cbf12b33618d5770e091f0225
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a suspicious domain. The document body, though heavily obfuscated, suggests a lure related to educational material. The presence of an external URI heuristic and ClamAV detection strongly indicates malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8293

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/award?keyword=synonym+worksheet+2nd+grade+pdf
    • http://antinomi.design/69466463441pjqqz.pdf
    • http://cookwellbakewell.com/angularjs_tutorial_for_beginners_step_by_step_free_downloadad1my.pdf
    • http://spoonnumberone.xyz/26568888415ibojv.pdf
    • http://brumbum2.xyz/latest_3d_games_for_laptop_free7y8hf.pdf
    • https://cdn-cms.f-static.net/uploads/4388825/normal_600a10f0d87ad.pdf
    • https://cdn-cms.f-static.net/uploads/4388422/normal_5fd118868e1c1.pdf
    • http://richteam.site/55252120931w4qe0.pdf
    • http://de-bewertung-889562.icu/attendance_management_solution_x100c3sx6k.pdf
    • http://negozio50sconto.info/bipezekitatuwefud1e9v8.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/e03881ce-8696-45be-ba57-d30b9e48d10e/10520610135.pdf
    • https://uploads.strikinglycdn.com/files/3f2ac0cf-92cb-4d8d-82fc-8c153bb8ff53/pexokoz.pdf
    • https://uploads.strikinglycdn.com/files/3672eb37-41c2-49c3-b5e4-70a6e2aa3943/tefutibelojikova.pdf
    • https://uploads.strikinglycdn.com/files/38bb6fa7-331c-40ef-b781-32339a927229/the_talented_tenth.pdf
    • https://uploads.strikinglycdn.com/files/d34a873a-fa2f-47da-86ea-1596d9d84d35/what_does_brayton_cycle_mean.pdf
    • https://uploads.strikinglycdn.com/files/33790529-3366-41d5-b426-06178f80ad95/gubibefobulivajeg.pdf
    • https://uploads.strikinglycdn.com/files/b086711c-3b74-45f9-8cad-4a40ce927208/a_connecticut_yankee_in_king_arthurs_court_how_many_pages.pdf
    • https://uploads.strikinglycdn.com/files/4f6887be-5801-4b2b-be80-10bd42172bf5/ultimate_ears_boom_3_bluetooth_waterproof_portable_speaker_ultraviolet_purple.pdf
    • https://uploads.strikinglycdn.com/files/0f496a9e-5961-429e-a780-86ab1abe33ed/what_university_is_best_for_business.pdf
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f2fa.bin
526c5a2175551476bef9e67e23fc16d118bda5f5d89964818a68e3a853678add
pdf-font-stream PDF embedded font (sfnt) at offset 0xF2FA 6476 bytes
font_01_sfnt_off00010301.bin
0744d148612af50b41ae02a7104f707679335f2cd48ce949bbd35eb76a481bfd
pdf-font-stream PDF embedded font (sfnt) at offset 0x10301 5916 bytes