Malicious PDF — malware analysis report

Static analysis result for SHA-256 220f1b0b69c3db9e…

MALICIOUS

PDF

71.2 KB Created: 2021-03-27 14:45:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-07
MD5: e6b153bf8fd5c9416c28689f8f9da734 SHA-1: 166ba0412fe296af35e5738db5bfa4fe8eff9b28 SHA-256: 220f1b0b69c3db9eaea7d7c76421577116fd823c81142d710cbfe752581eaa5e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains an embedded URL pointing to a resource that is likely a lure for malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically phishing. While no scripts were directly extracted, the presence of external URIs and the nature of the detection suggest the PDF is designed to trick users into downloading further malicious payloads, likely by masquerading as a legitimate document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=gizmo+electromagnetic+induction+answer+key PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4418401/normal_604b18079f76c.pdfIn PDF document text
    • http://dinusedixiwog.iblogger.org/fasukudugoxetonuxiti.pdfIn PDF document text
    • http://mitedujonajezed.scienceontheweb.net/47613422261.pdfIn PDF document text
    • http://doctorzlo.com/xakoxidusizuzen6e16s.pdfIn PDF document text
    • http://rasprodavaika.ru/61652966558tv6s6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4480732/normal_6047a56ddfd83.pdfIn PDF document text
    • http://nuzadovokebin.iblogger.org/google_chrome_free_for_windows.pdfIn PDF document text
    • http://beamorem.com/29793761229odpwk.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/fipijife/jolixaxidefunivajoxu.pdfIn PDF document text
    • http://surotatifezuxe.rf.gd/dell_support_windows.pdfIn PDF document text
    • https://s3.amazonaws.com/xotomisen/81071075994.pdfIn PDF document text
    • https://s3.amazonaws.com/xisakazelelinim/janatha_garage_ringtones_320kbps.pdfIn PDF document text
    • https://s3.amazonaws.com/padadutiseni/damez.pdfIn PDF document text
    • http://kawisud.rf.gd/46618660651.pdfIn PDF document text
    • https://s3.amazonaws.com/xujitezu/age_to_read_trials_of_apollo.pdfIn PDF document text
    • https://s3.amazonaws.com/semuxemakaw/magupepare.pdfIn PDF document text
    • https://s3.amazonaws.com/tixeligufokup/tojatekemuzekij.pdfIn PDF document text
    • https://s3.amazonaws.com/mogedozara/34157474888.pdfIn PDF document text
    • http://mafefelanepule.epizy.com/negative_impacts_of_globalization.pdfIn PDF document text
    • https://s3.amazonaws.com/fuvidokibet/singer_44s_heavy_duty_sewing_machine_manual.pdfIn PDF document text
    • http://dirulibas.onlinewebshop.net/28317087948.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d9d1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD9D1 5600 bytes
SHA-256: 279f4e486a7b5f4e13397f9eb0ae9aaaebe9baaf4315eefefff88e7c94e79191
font_01_sfnt_off0000ecec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xECEC 10024 bytes
SHA-256: 7e747699c12d3d7156c2f4353725cc92c8ed693b56992bb6d7ee28c5f058d1ba