Malicious PDF — malware analysis report

Static analysis result for SHA-256 21dada025464f3d8…

MALICIOUS

PDF

396.7 KB Created: 2021-03-14 09:57:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 52a6ee556d8d685f749dcc0aebc7d5a3 SHA-1: 7c310a203033f4912155228f839f4fab12a9d691 SHA-256: 21dada025464f3d8b17321e7d39031fef707a133bf578baf610927fe2defe4cb
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that leads to a domain associated with malicious activity, as indicated by the ML classifier and ClamAV detection. The 'SE_CALLBACK_LURE' heuristic suggests a phishing or tech-support scam pretext, aiming to trick users into visiting the provided URL. While no scripts were explicitly extracted, the PDF structure and embedded URI are strong indicators of a malicious intent to redirect users to a potentially harmful site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9033

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=digimon+cyber+sleuth+digivolution+guide+pdf
    • http://fabermanufacture.ru/90968710571zboy6.pdf
    • http://sesizuxewewax.mygamesonline.org/fedex_locations_elkins_wv.pdf
    • https://cdn.sqhk.co/bupabumo/iai8zlX/spqr_a_history_of_ancient_rome_book_review.pdf
    • http://pivolirarorip.mypressonline.com/6453615672.pdf
    • https://wuvobarapupi.weebly.com/uploads/1/3/0/8/130813490/wakipevameneze.pdf
    • https://cdn.sqhk.co/tovipovo/hkgiPQm/zigzagoon_evolution_form.pdf
    • http://goldotzyv.ru/why_would_my_kindle_not_turn_onhpyjm.pdf
    • https://lepoxaxilil.weebly.com/uploads/1/3/4/4/134498836/2129355.pdf
    • http://hookup757.fun/bsplayer_free_full_version_windows_7zjegu.pdf
    • http://getbuiss.online/the_cambridge_history_of_warfare_geoffrey_parker6b59l.pdf
    • http://leririv.sportsontheweb.net/how_to_charge_ion_tailgater_speaker.pdf
    • https://suwuvonujijipi.weebly.com/uploads/1/3/4/0/134042364/bogabekuwir-rovifadus.pdf
    • http://xoxuvajes.mywebcommunity.org/accounting_books_for_beginners.pdf
    • https://woraragupawajup.weebly.com/uploads/1/3/2/6/132681931/daserazov.pdf
    • http://salizurewaki.mypressonline.com/46574919266.pdf
    • http://mjawebdesign.net/hermeneutics_principles_and_processes_of_biblical_interpretation1gu42.pdf
    • http://jadogaxarabu.mygamesonline.org/72546434145.pdf
    • https://mafaredoli.weebly.com/uploads/1/3/2/6/132695491/5305232.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://xijejuvi.myartsonline.com/what_is_the_toughest_sql_query_optimization.pdf
    • https://uploads.strikinglycdn.com/files/d6c109e9-e595-4796-9ecc-acd5d449e790/48170459929.pdf
    • https://uploads.strikinglycdn.com/files/821c3e27-0c60-4691-a173-118e1f27888f/dijewetudivubizugaj.pdf
    • http://ritumogadoj.onlinewebshop.net/64870549832.pdf
    • https://uploads.strikinglycdn.com/files/5cb0c58b-845c-4261-8823-038b61315eb1/documentary_letter_of_credit_cost.pdf
    • http://felugibesixe.onlinewebshop.net/damn_good_friends_quotes.pdf
    • https://uploads.strikinglycdn.com/files/197c81e7-c974-4fff-8fef-0b1c98979ba5/ladojorapususa.pdf
    • http://dipagepe.atwebpages.com/pevotowibopimofoxokezufuv.pdf
    • https://uploads.strikinglycdn.com/files/c0c08d41-7768-4766-a290-f6df7c079e0f/cavaliere_island_range_hood_manual.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off00052829.bin
ec30b96a9371631b8343cf61a45d150560251d2bc9b319431286943cce65ee5d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x52829 63240 bytes
font_01_sfnt_off0005e457.bin
e85635c5a9d19f0a38fa24ec00c26950da4ad302d684d3918dab24b912173197
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E457 5660 bytes
font_02_sfnt_off0005f77d.bin
568398b83649030462b603d7e6c18a3b6fdd23a86cb167bdaecaf4b0db8c1e84
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F77D 13240 bytes