Malicious PDF — malware analysis report

Static analysis result for SHA-256 1bdd7b86c39cd5da…

MALICIOUS

PDF

109.1 KB Created: 2021-05-03 20:31:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b62fdb79e2ea3c082bdf1045ae64ecd1 SHA-1: 9b2e0a1bfc51373fbed6ffa480f3ee7bc05910c8 SHA-256: 1bdd7b86c39cd5daeee068b042851d9e809568195fe6b982bd5322de1f5561af
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by a machine learning classifier and ClamAV. It contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The document body is heavily obfuscated and unreadable, but the presence of the external URI and the high ML score indicate a malicious intent to redirect the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=denon+avr+1910+best+settings
    • https://cdn.sqhk.co/mujowofapubi/xeifjcD/dual_screen_anime_wallpaper.pdf
    • http://zevewidojodot.mywebcommunity.org/is_the_canon_ts3322_printer_compatible_with_chromebook.pdf
    • https://cdn.sqhk.co/sirepajaku/jN6gfhi/need_for_speed_most_wanted_remastered_download.pdf
    • http://springtea.space/future_song_mp3_downloado0btq.pdf
    • http://apparently-home.com/how_long_does_it_take_to_charge_studio_3_beatsr57fc.pdf
    • https://cdn.sqhk.co/wujozuzewed/cczjjnN/91888042606.pdf
    • http://my-credit.info/calendar_method_of_contraceptiona5asu.pdf
    • http://zuvels.xyz/dupokulugejktifb.pdf
    • http://znasila.ru/amma_bhagavan_video_songso8595.pdf
    • http://pasikufopubiwo.mypressonline.com/jetuk.pdf
    • http://solusaxisabo.scienceontheweb.net/central_limit_theorem_worksheet.pdf
    • http://vowugewekoperak.iblogger.org/bleach_brave_souls_apk_9._0._4.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/3f150359-f21e-4802-ae3a-b1fd2ff8d24d/how_to_remove_blocked_calls_from_panasonic_phone.pdf
    • https://uploads.strikinglycdn.com/files/3d52598b-e58d-4eef-b304-2596044ca9f8/xavezotan.pdf
    • http://releboxodaw.rf.gd/23812014148.pdf
    • https://uploads.strikinglycdn.com/files/919ddf3a-018e-416e-b3d1-995b98a50bd7/pelupiwugosuxilu.pdf
    • https://uploads.strikinglycdn.com/files/7d34a643-de32-4319-b3a2-460b385b5c7c/what_can_be_cooked_on_a_griddle.pdf
    • http://lesexugisitu.rf.gd/why_is_my_xfinity_x1_box_not_working.pdf
    • http://sepenoneregepe.rf.gd/80852294779.pdf
    • https://uploads.strikinglycdn.com/files/7c78d169-c054-40a5-9441-9b4dcfd875e2/16534813788.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00015a19.bin
1bbfae5570ea60d9f65e6751476f4459c08542307e6e8d495ea52321d4c9a560
pdf-font-stream PDF embedded font (sfnt) at offset 0x15A19 5368 bytes
font_01_sfnt_off00016c7b.bin
52180c1af7e60322dab0e904b54ca57c28938685f231dd8d8b4756587023319c
pdf-font-stream PDF embedded font (sfnt) at offset 0x16C7B 10908 bytes
font_02_sfnt_off000191be.bin
e93acd332f5893643511f4cefd38969ad5c744ad1b08842a788b6be7d277dd15
pdf-font-stream PDF embedded font (sfnt) at offset 0x191BE 16204 bytes