Malicious PDF — malware analysis report

Static analysis result for SHA-256 271bc9a550d8b100…

MALICIOUS

PDF

84.1 KB Created: 2021-03-28 18:23:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 05bd110bc59d260f73d0b72728ee0151 SHA-1: 22f1f6f54b1885fb2a80198e2668a3faaf19de93 SHA-256: 271bc9a550d8b10056c03de9fa1ff4ca2b48ff6cffa1876e0c51b99ea126f016
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, which is a strong indicator of a phishing or malware distribution attempt. The ML classifier and ClamAV detection further support the malicious nature of the file. While no scripts were explicitly extracted, the presence of embedded URLs and the overall detection suggest the document is designed to redirect users to malicious content, likely for phishing or to download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/award?keyword=kp+astrology+books+in+bengali+pdf PDF link annotation
    • http://japarof.mywebcommunity.org/sql_server_tutorial_for_beginners_with_examples.pdfIn PDF document text
    • https://cdn.sqhk.co/wamamuli/jafSjc7/walizabufo.pdfIn PDF document text
    • http://zonagareme.getenjoyment.net/7238689694.pdfIn PDF document text
    • http://tadidavazutopa.sportsontheweb.net/agritourism_in_maharashtra.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4496592/normal_6040aaf1bd994.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4500453/normal_5fc8d5bf4c152.pdfIn PDF document text
    • https://cdn.sqhk.co/suxujaba/bghjfhh/68961395908.pdfIn PDF document text
    • http://arbitestpark.xyz/63955427283f3st3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4456398/normal_605ca8bb6e647.pdfIn PDF document text
    • http://guzoseta.getenjoyment.net/jurebirijalitidatesufor.pdfIn PDF document text
    • https://cdn.sqhk.co/vipikunowi/jBiehcI/online_auctions_cincinnati_ohio.pdfIn PDF document text
    • http://1green.space/validity_performance_meaningzxfx3.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4485435/normal_5fc592251ecc3.pdfIn PDF document text
    • http://cmbespaceclient.xyz/netbeans_java_ide_android9vtwq.pdfIn PDF document text
    • http://paktum.pro/best_alkaline_food_chartk6tds.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://s3.amazonaws.com/fizup/cuanto_es_10_gramos_en_cucharas.pdfIn PDF document text
    • https://s3.amazonaws.com/sakaburepagase/calendars_2020_templates.pdfIn PDF document text
    • https://s3.amazonaws.com/bajuse/rekidaludibewa.pdfIn PDF document text
    • http://sogurorirerew.onlinewebshop.net/30528546456.pdfIn PDF document text
    • https://s3.amazonaws.com/jixerubowi/dewezalakoluvifedarulural.pdfIn PDF document text
    • https://s3.amazonaws.com/borokegujuzero/radio_shack_electronics_learning_lab_28-280.pdfIn PDF document text
    • https://s3.amazonaws.com/limewub/jofurebifobir.pdfIn PDF document text
    • https://s3.amazonaws.com/zewimu/wikofixokelawume.pdfIn PDF document text
    • https://s3.amazonaws.com/dazuxujepov/layered_armor_guide_mhw.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb31.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB31 5484 bytes
SHA-256: 7a262dfbe74aa8d1cc1f65c5a38434004ac6a5aa1c1d92328a6322211bad44b9
font_01_sfnt_off0000fde9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFDE9 6080 bytes
SHA-256: 51908ad744cdb7d536b9f6cf405d2b4bb2e4c720b385224a7e9893f6e7170275
font_02_sfnt_off000111b9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x111B9 10600 bytes
SHA-256: 9ce79364528715841c5587f7d42e196ada92dda6332cefea923d365d8354f336
font_03_sfnt_off00013649.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13649 2992 bytes
SHA-256: abea13d2942ae6af28af52ff77f1192584af4ef6bbbd69905417f4b4e5d620da