Malicious PDF — malware analysis report

Static analysis result for SHA-256 1ff33ff0faf2f2dc…

MALICIOUS

PDF

61.9 KB Created: 2021-05-08 18:30:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0f8a13f5be078f7a17c2ead8186546a4 SHA-1: 74aa5a7b27e3d39a02311b2a09bc8c509bf26623 SHA-256: 1ff33ff0faf2f2dcbce88d798fd742c5494be46eb2aa18ec7513907099dec494
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating it is likely a phishing or trojan delivery mechanism. The presence of multiple embedded URLs suggests an attempt to redirect the user to malicious sites or download further payloads. The document body is heavily obfuscated, preventing a clear understanding of the specific lure, but the overall structure points to a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8123

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dok-vo.ru/userfiles/file/74876005633.pdf
    • https://www.reachcast.ca/wp-content/plugins/super-forms/uploads/php/files/e2d7313f914d6d70fa1ac2c57921e86b/devikifotenusovomitusita.pdf
    • http://www.wallisandemmanuel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607bf217f083f---26135021962.pdf
    • https://webtraffic.ch/wp-content/plugins/super-forms/uploads/php/files/met3i0k2s0i0boflr9plpj2odu/kuxinepeponurubajojubabin.pdf
    • http://ne-moloko.ee/wp-content/plugins/super-forms/uploads/php/files/baa59def76ca83e9b22fcaf0739ee481/65082991751.pdf
    • https://webhostmurah.com/wp-content/plugins/formcraft/file-upload/server/content/files/160922d993b197---28508404203.pdf
    • http://kraljicabih.com/wp-content/plugins/formcraft/file-upload/server/content/files/16073d3aeccea8---zidivubidajeju.pdf
    • http://www.psstrecno.sk/wp-content/plugins/formcraft/file-upload/server/content/files/16082b6e3d3ac3---wukevedenitiset.pdf
    • https://webmodeli.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075a1325e89a---kuzebapomefu.pdf
    • https://xn----7sbabak5acz7byau.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/df4ba44bc4681bcf103bbbdfe7b5b0b7/50802684556.pdf
    • https://www.fecomerciomg.org.br/wp-content/plugins/formcraft/file-upload/server/content/files/160790915c1a4a---70815215866.pdf
    • http://nuyewpilot.academy/wp-content/plugins/super-forms/uploads/php/files/8b06f3b463dab3d2d3751a4ce1364c1d/xonere.pdf
    • https://kodeac.com/wp-content/plugins/super-forms/uploads/php/files/nq46m6choibo51fvn1at6qbcpf/3767137026.pdf
    • http://cricalliance.com/wp-content/plugins/formcraft/file-upload/server/content/files/16086afef21caf---bilofikefined.pdf
    • http://uat.ideadunes.com/projects/ideadunes-portfolio-site/wp-content/plugins/formcraft/file-upload/server/content/files/16083d5020234b---zetawoseroginagupo.pdf
    • https://saftanton.dk/wp-content/plugins/formcraft/file-upload/server/content/files/1606d4555eea03---tubowomej.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=billboard+music+awards+2017+performances
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cee1.bin
2257cd4925c03057b57d8c350104415c2d8fe59fa74cb189e54679f4d392107e
pdf-font-stream PDF embedded font (sfnt) at offset 0xCEE1 5988 bytes