Malicious PDF — malware analysis report

Static analysis result for SHA-256 25573112f3eaf669…

MALICIOUS

PDF

84.4 KB Created: 2021-06-05 18:30:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 13389483b08db2104a548e136bda8d0d SHA-1: e6551a2c4bb3196d6b6c47deccf1f8458d3487df SHA-256: 25573112f3eaf6694cc67314362e4b23f90a4f5d54c6ce13f56dc2a53c9eb77c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The embedded URL points to a resource that appears to be a download link for game mods, likely a lure to trick users into downloading malware. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://catamma.ru/uplcv?utm_term=ets2+bus+mod+indonesia+apk+game+download
    • http://cokhibaosang.com/media/ftp/file/63188782232.pdf
    • https://victory-agency.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ade4847fb1a---30889618291.pdf
    • http://ophtalmic-overnight.fr/wp-content/plugins/formcraft/file-upload/server/content/files/160abfa4b263ac---36670132660.pdf
    • https://airflow-skateboards.com/upload/file/jatavukudepigasoxuwefas.pdf
    • http://cageart.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160733e3b8cab6---jelugu.pdf
    • http://www.kissdocs.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16075659cbaeba---97742946866.pdf
    • http://az4group.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160aa68245f091---fufosobesut.pdf
    • http://gingerwooddesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b0df7e7bc6a---xuxavigik.pdf
    • http://ne-moloko.ee/wp-content/plugins/super-forms/uploads/php/files/d0fd31e713b9c3947d4ad43aa9300b78/guratotivugixixute.pdf
    • http://www.kliningstroy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16080289278bf0---87124175610.pdf
    • http://juniorsmagazine.com/wp-content/plugins/formcraft/file-upload/server/content/files/160849a8cabed6---74607381501.pdf
    • https://nevisnews.com/userfiles/suzowevilobatutos.pdf
    • https://2greenchicks.com/wp-content/plugins/super-forms/uploads/php/files/7e07552128595a0f230c51c69122b8eb/1111749032.pdf
    • http://svenstavik.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ad6bc660124---73933076255.pdf
    • http://unseenadventure.com/userfiles/file/27375554409.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebc3.bin
d51021c3b90c45d9308c1fd48f928cae41a6ef42790d7e6d1a75c9cfb1b5d108
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBC3 5568 bytes
font_01_sfnt_off0000feb1.bin
e6b41424cbfbab56785d1d111fff896518f16f9ecc2d4d57a6cdabbdaf1573d2
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEB1 2076 bytes
font_02_sfnt_off000107bf.bin
c9ed90569921e7c3bee4385f83d5bc8e85aa30e601522424647a25f98bbd67d5
pdf-font-stream PDF embedded font (sfnt) at offset 0x107BF 10940 bytes
font_03_sfnt_off00012d6a.bin
977e19fdf8502e5ba34551f426002a740a7b5d31f74097d87d9fcf5a042eaa14
pdf-font-stream PDF embedded font (sfnt) at offset 0x12D6A 16684 bytes