Malicious PDF — malware analysis report

Static analysis result for SHA-256 2204ef00893e35b5…

MALICIOUS

PDF

78.7 KB Created: 2021-03-19 20:40:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dddef4a051f6016d90cc15d8f3d1258f SHA-1: dd8ed286ed34e222d389574ee4645170fe62935b SHA-256: 2204ef00893e35b56169c2826d43a2493fb4054901e55f1811f9562c79020c87
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It contains an embedded URL that leads to a suspicious domain, likely intended to host malicious content or phishing pages. The document body, though heavily obfuscated, contains text that appears to be a lure related to 'Head boy of ravenclaw'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=head+boy+of+ravenclaw
    • https://cdn-cms.f-static.net/uploads/4369769/normal_601bb94f1923f.pdf
    • https://static.s123-cdn-static.com/uploads/4498882/normal_5fcba0cc6fbfb.pdf
    • https://cdn.sqhk.co/pizililiv/ige3ev5/little_heroes_academy_clarksville_tennessee.pdf
    • https://static.s123-cdn-static.com/uploads/4375070/normal_5fce6f39bca42.pdf
    • http://porizaritofo.mypressonline.com/best_lower_back_stretches.pdf
    • https://cdn.sqhk.co/kafodarifab/dkcgYhe/90130653918.pdf
    • https://static.s123-cdn-static.com/uploads/4413707/normal_5ff773ec669e7.pdf
    • http://nulivanofika.mygamesonline.org/automotive_battery_testing.pdf
    • http://pejelurim.getenjoyment.net/how_to_find_the_amount_of_grams_in_a_compound.pdf
    • http://toworugesolur.getenjoyment.net/demaritavez.pdf
    • http://mosebuzixat.mywebcommunity.org/frayer_model_template_math.pdf
    • http://nalodorepuwag.getenjoyment.net/holy_quran_english_translation_book.pdf
    • http://xiguxivevov.sportsontheweb.net/mujinivamexerexog.pdf
    • https://cdn.sqhk.co/fugapaloter/bhiTCif/tecnologias_de_la_informacin_ejemplos.pdf
    • https://cdn-cms.f-static.net/uploads/4382407/normal_6049b2502d93d.pdf
    • http://winovigamaj.mygamesonline.org/86249264113.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://e114ad41-1367-46fe-a5fd-427bf640f69d.filesusr.com/ugd/a63c55_b8e861ed8e78442da858e3b13cca336c.pdf?index=true
    • http://tevefetilojas.atwebpages.com/2002_ford_explorer_4.0l_engine_diagram.pdf
    • http://koriwironawuva.myartsonline.com/meningitis_classification.pdf
    • https://31c8a3d4-0132-49f1-a04f-09c79d03e01f.filesusr.com/ugd/a4da84_b8fdb915ef75424981202003c8b93f23.pdf?index=true
    • https://bf808793-8b46-4c54-8b11-319763181fa0.filesusr.com/ugd/0d018b_fb08c65142574c77937ff3f41ddc501e.pdf?index=true
    • https://c63ca81c-6df4-4ec3-bc2e-8508f29a6879.filesusr.com/ugd/d48fe3_56a61b79bc1440c5b3391ac4e0dfbff0.pdf?index=true
    • https://cfecb619-c0f5-418d-ae9d-b1147643389f.filesusr.com/ugd/4cd51e_67e1dca506464363b7bb8b7754b5bf31.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f520.bin
5c03f0d273622acfc665a40e2a31cadf9bd222d50e2ae5163ca49b5b307e26db
pdf-font-stream PDF embedded font (sfnt) at offset 0xF520 5192 bytes
font_01_sfnt_off000106f2.bin
8fe79f233ec80c52d02a063f2f1126ecf53e48c27f13c34b53c27556f47568b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x106F2 11664 bytes