Malicious PDF — malware analysis report

Static analysis result for SHA-256 28d38c87543e47b3…

MALICIOUS

PDF

88.9 KB Created: 2021-03-23 15:34:09 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 25f431c16636fafc28d31a31e61e398f SHA-1: 7fe21fcea7570b8484f750a4619a277a481089c6 SHA-256: 28d38c87543e47b3fbc93204733537efb09cd90b1571ef62cf8d037f8f23d4c4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that mimics a search result, likely to trick the user into visiting a malicious site. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically phishing. While no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it's designed to lead the user to external malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/award?keyword=seamless+pipe+sizes+in+mm+pdf
    • https://cdn.sqhk.co/loxowopiv/hg8gdXA/kontrapunkt_musik_beispiel.pdf
    • https://zevixaxilifudex.weebly.com/uploads/1/3/4/1/134131629/kijulunosura-saxakafotikusu.pdf
    • http://gutagige.sportsontheweb.net/proceso_de_investigacion_cualitativa.pdf
    • https://cdn.sqhk.co/terexugureto/jYwjhhg/florida_llc_annual_report_deadline.pdf
    • https://retowukiri.weebly.com/uploads/1/3/4/5/134592720/kagedobedusun.pdf
    • http://talebakela.iblogger.org/us_fda_adverse_event_reporting_timelines.pdf
    • https://nirodafudo.weebly.com/uploads/1/3/4/6/134697392/wapunagiwolupitapixe.pdf
    • https://cdn.sqhk.co/fekigimuzib/gdhKhcq/wifanibikifedenabavu.pdf
    • https://cdn.sqhk.co/vafizolubev/LVirajg/popular_city_warangal.pdf
    • http://xagowawusik.66ghz.com/85092552043.pdf
    • https://fedoxamanisoru.weebly.com/uploads/1/3/4/6/134668372/jadisepawute_xuwuwimuret_fogatowikep_wowijidabiro.pdf
    • https://xasevezivim.weebly.com/uploads/1/3/5/3/135302984/3216460.pdf
    • https://cdn.sqhk.co/gizivapejoko/dcxje0E/11385810626.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://todifotitidowos.epizy.com/2002_toyota_hiace_radio_wiring_diagram.pdf
    • http://fefemegazo.rf.gd/ariel_s_beginning_full_movie.pdf
    • https://s3.amazonaws.com/fadobirak/velometizuduralim.pdf
    • https://s3.amazonaws.com/jijari/85568273687.pdf
    • https://s3.amazonaws.com/lewuli/how_to_install_respironics_filter.pdf
    • http://jemavasaw.rf.gd/biology_dictionary_book.pdf
    • http://gonatiw.rf.gd/nawonugezagogobogikabida.pdf
    • http://rosajeku.myartsonline.com/domino_s_pizza_menu_download.pdf
    • http://vegozuw.epizy.com/aurora_runaway_ringtone_free.pdf
    • https://s3.amazonaws.com/lekizopiloref/34222659702.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011b59.bin
6c21b81ce00f91bf1ba3c8f6cd9dadbf27ec532c5258db3d911085abb3e618db
pdf-font-stream PDF embedded font (sfnt) at offset 0x11B59 5244 bytes
font_01_sfnt_off00012d2b.bin
c94c64cf98ee5899f36744dfaaea52bb97fbbe512e9eef1d2662e938df47dc01
pdf-font-stream PDF embedded font (sfnt) at offset 0x12D2B 12180 bytes