Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d75b6694c99163f…

MALICIOUS

PDF

75.9 KB Created: 2021-03-15 19:44:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 65dc667d561a9ef007cafb645e38603f SHA-1: 8eda5de0a9367da5133051dc5f81fba5dadd4d15 SHA-256: 1d75b6694c99163fb3fd9961d94b1c7810033d6e3588164a9279a037fdaad569
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Phishing.Trojan' and an ML classifier indicating maliciousness. The 'SE_CALLBACK_LURE' heuristic specifically points to a callback phishing or tech-support scam pretext. While no scripts were extracted, the presence of embedded URLs, particularly 'https://midufefew.ru/wix?keyword=steve+vesey+cpa+danvers+ma', suggests an attempt to direct the user to a malicious site, likely to further the scam or deliver a payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=steve+vesey+cpa+danvers+ma
    • http://proita.space/hardware_components_of_computer_network_pptbicfx.pdf
    • https://static.s123-cdn-static.com/uploads/4379849/normal_6006386bea0b1.pdf
    • http://cloudmarket.website/11767665810idvfs.pdf
    • http://zoneeuro.pro/free_movie_catarina_and_the_othersw0366.pdf
    • https://static.s123-cdn-static.com/uploads/4488807/normal_6000fccd1db3d.pdf
    • https://static.s123-cdn-static.com/uploads/4458623/normal_5ffc9d0ee8806.pdf
    • https://puzugisebo.weebly.com/uploads/1/3/1/4/131438758/nebagaju.pdf
    • http://getliterate.online/the_magicians_season_1_episode_6_watch_onlinevpamb.pdf
    • https://furamakivagoj.weebly.com/uploads/1/3/0/8/130814247/basogajed.pdf
    • https://static.s123-cdn-static.com/uploads/4382779/normal_600190cfdd913.pdf
    • http://glossywp.online/ethical_considerations_in_psychological_assessment0hv2p.pdf
    • https://cdn-cms.f-static.net/uploads/4483604/normal_60240e72246c2.pdf
    • http://test123test.xyz/18044417104g56oq.pdf
    • http://mirror-x.org/resumen_sobre_el_libro_de_los_seores_del_narco4qjy5.pdf
    • https://pesurejipani.weebly.com/uploads/1/3/4/2/134234892/2cbcf8fafae7ceb.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://f74ea38a-ab8d-49a0-8d31-9a1d7ce64423.filesusr.com/ugd/5ceade_7b8a010207944c7a981fc401b877401f.pdf?index=true
    • https://uploads.strikinglycdn.com/files/4c8b0d78-f86b-4240-9a58-0ed7e747d816/19399585821.pdf
    • https://uploads.strikinglycdn.com/files/0b3e3751-614f-440f-a212-25aac81fce0b/viluzugudivusoxijofu.pdf
    • https://911f1565-2faa-4874-b261-330d521e7362.filesusr.com/ugd/f46427_2f6f99930a5645ca8ddc4c9c517d89ef.pdf?index=true
    • https://12dd324c-696b-4d67-8c19-991f3eacec2c.filesusr.com/ugd/eeb7bd_9a3d30717ef34c9493cf98b42dc89342.pdf?index=true
    • https://681956c7-2c57-495f-b996-d04b50c745b0.filesusr.com/ugd/907d98_01a556aaa16e4ed6ba1569d443e991f9.pdf?index=true
    • https://0f8fedcd-12c0-4678-86f8-e2bff7269121.filesusr.com/ugd/70e7d4_a152f6fa6d8740a69b3d39e091a00072.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e838.bin
67c09dbdedb3750d8d2aa631b68bf3e8e62484f5296c31e1ac86df5349893bb1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE838 5452 bytes
font_01_sfnt_off0000fabe.bin
0002114b76415fc1166ea3c80cd6502e68cad8a8a6091df0d2d4c5b5b1ce1998
pdf-font-stream PDF embedded font (sfnt) at offset 0xFABE 11708 bytes