Malicious PDF — malware analysis report

Static analysis result for SHA-256 20015c6ecdb28ddd…

MALICIOUS

PDF

76.8 KB Created: 2021-03-15 02:28:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e6f929d01be47ce0fbf1c7c942d933c3 SHA-1: fb58d38646ea0067c31af21040342075c0221080 SHA-256: 20015c6ecdb28ddd7dea7b6ac5163efc0c234ac7833ae17fa01de1d02210b1dd
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains embedded URLs that lead to potentially malicious content, as indicated by ClamAV detection as Pdf.Phishing.Trojan. The heuristic firings suggest the document is designed to trick users into downloading further malware by masquerading as a legitimate PDF file. No scripts were extracted, but the presence of multiple suspicious URLs indicates a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4910

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wb?keyword=500%20most%20common%20words%20in%20english%20pdf
    • http://wowit.pro/vumidezapuwenoluxugarofescs07a.pdf
    • http://cabinetsly.xyz/pet_sematary_1989_full_movie_free_download6ljce.pdf
    • http://helplnstagram-confirm.com/where_the_wild_things_are_quotes_imdbbqp63.pdf
    • https://wudujadulaneg.weebly.com/uploads/1/3/0/7/130738887/gijepusaxeji_pavafa_nawatafigot.pdf
    • http://sentytld.online/fudugomumuzuripiwuxikekcj42.pdf
    • http://lapitubemexidi.mywebcommunity.org/what_is_the_command_to_list_all_files_in_a_directory.pdf
    • http://poxumanavofeboz.scienceontheweb.net/22757051604.pdf
    • https://fitepavi.weebly.com/uploads/1/3/4/4/134485464/88198.pdf
    • https://wojazaxu.weebly.com/uploads/1/3/4/5/134589930/16197.pdf
    • http://xufuxenu.mypressonline.com/how_to_design_a_website_using_html_and_css_with_example.pdf
    • http://yildirimotobursa.com/historia_de_la_contabilidad_electronica_en_mexicov9qks.pdf
    • http://werojati.getenjoyment.net/livogusirulod.pdf
    • http://maddot.space/how_to_replace_my_keurig_water_filters0dt3.pdf
    • http://lamanixumerad.mypressonline.com/samsung_galaxy_tablet_model_gt-p3113ts.pdf
    • http://visunuduxat.mypressonline.com/biostatistics_journal.pdf
    • http://mitedujonajezed.scienceontheweb.net/gse_algebra_1_unit_1_relationships_between_quantities_and_expressions_study_guide.pdf
    • http://scandisvet.ru/chess_rush_guide_frjoex1.pdf
    • http://belkwigs.com/sotujaronafesoe92e9.pdf
    • http://gejurabek.getenjoyment.net/nikon_coolpix_p610_instruction_manual.pdf
    • http://letgtma.bid/26478458363dtl2e.pdf
    • http://strgb2.ru/rimijufuvenijunie7nzi.pdf
    • http://znohist.site/mere_christianity_book_3_chapter_7_quizletbmjrb.pdf
    • http://twirlini.com/rounded_corners_processingiuiyy.pdf
    • https://kutinimi.weebly.com/uploads/1/3/4/6/134608846/radesiraxuru_wakeziroxim_topunisi_lajif.pdf
    • https://lugonejiborin.weebly.com/uploads/1/3/5/3/135336075/vodusiva.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://faxiruvud.myartsonline.com/xixuwugulitusemujawizeze.pdf
    • http://jasunusemoki.onlinewebshop.net/descargar_musica_de_anthony_santo_popurri.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f804.bin
dcd177f3d81d38a97026e6516f3e27744546bb16458dae8f602d18f9ffb1591a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF804 5412 bytes
font_01_sfnt_off00010a47.bin
e5865dcc1161209506863715c6908edda07b84baf49c831a02655d7cc79611bc
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A47 10580 bytes