Malicious PDF — malware analysis report

Static analysis result for SHA-256 265d20efb69a8c95…

MALICIOUS

PDF

84.4 KB Created: 2021-06-30 22:50:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 94454529ded5e4411ef7e8343f3db864 SHA-1: 2f2f9aaec7f3195599e3ff32bf8941a14b285f5e SHA-256: 265d20efb69a8c957bf55b783b74bc9af53f762486ec4e359df925f55a8c8adf
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, likely intended to host malicious content or redirect the user. The document body is heavily obfuscated, but the presence of the external URI and the ClamAV detection strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9860

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://laborke.ru/uplcv?utm_term=red+dawn+123movies+2012
    • https://stcatherine.ac.ug/wp-content/plugins/formcraft/file-upload/server/content/files/160a55e3911527---wumoj.pdf
    • http://kraljicabih.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aa36cb1455e---vudijofifatefiwowuximotub.pdf
    • https://sellos-mecanicos.com/wp-content/plugins/super-forms/uploads/php/files/0ff606edb7ecfe5d2162094d737d9dc7/bukigusimuwamezidevakid.pdf
    • https://alphaveneers.co.uk/wp-content/plugins/super-forms/uploads/php/files/9b74e552910ced25f2ab52d001cd50c7/jijivemabagaxowelenutak.pdf
    • https://evermoral.hk/upload/file/1624498867.pdf
    • http://www.mondzorgvesa-voorschoten.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607aab9a95318---pumomedawubokutufixono.pdf
    • https://advicezone.org.uk/wp-content/plugins/super-forms/uploads/php/files/9ejgshouupbor6sj18nij3ekdm/zegekuwa.pdf
    • https://apz-arte.com/ckfinder/userfiles/files/boxib.pdf
    • https://www.hagensmarketing.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a7f4b52e5b---jubajaralo.pdf
    • https://hotelritariccione.it/wp-content/plugins/formcraft/file-upload/server/content/files/160c64230d4903---pitotawalezedemepi.pdf
    • https://doktor-ara.com/userfiles/files/56220441871.pdf
    • http://abwlanham.com/uploads/files/52571950775.pdf
    • http://andreevmag.com/wp-content/plugins/super-forms/uploads/php/files/7f5396927766a94db34b1ccd45ea3749/63703857095.pdf
    • https://beautyreviveshop.com/newerac2c/userfiles/file/gedosojanixafapipatefamo.pdf
    • http://iccj.jp/images/uploads/fckeditor/file/bexetipibiladateni.pdf
    • http://bendhorseride.com/userfiles/file/febizibasunodedel.pdf
    • https://okazdedziecko.pl/_files/Media/file/33788087191.pdf
    • https://art-gallery.mn/uploads/files/51912232580.pdf
    • https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/e82e84b74cf957963bbd75b00b9c954e/2685184124.pdf
    • http://kpdb.org/userfiles/files/papikodupemurukajemi.pdf
    • https://accesoriosalmayor.com/images/userfiles/file/81957386789.pdf
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609841134d749---17588306013.pdf
    • https://afanasyev-design.ru/wp-content/plugins/super-forms/uploads/php/files/baa957c23c27c3fd8e455917f0a142d8/51944669648.pdf
    • https://kovtec.pl/eurostyl/photos/file/tiwaviribefuba.pdf
    • https://3dreamstudios.com/wp-content/plugins/super-forms/uploads/php/files/46f132bfab70d259e63cd2366d84a9ca/87439755850.pdf
    • http://md-servicios.com/userfiles/file/benadumefejikubawike.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e4dd.bin
17ef3b2dc35d4b94aecc02298a5d67162357a460117b973dfb63d094ecdd2362
pdf-font-stream PDF embedded font (sfnt) at offset 0xE4DD 17556 bytes
font_01_sfnt_off000112f0.bin
28b0b7a5b796a3ac5656dac329b1e4ad222a14edfcc76a2f4f2cc61253b3c400
pdf-font-stream PDF embedded font (sfnt) at offset 0x112F0 10828 bytes
font_02_sfnt_off00012c16.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12C16 16792 bytes