Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a5540a74a8d0472…

MALICIOUS

PDF

73.4 KB Created: 2021-03-09 05:12:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c32d9f0dc6d1647729648709ca96f462 SHA-1: 9a65ab972fba90fe3dee79cac92822d270323e8a SHA-256: 2a5540a74a8d04720d9feb55e9cde2bf58d9a747206f40151036bdfd67b20724
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains heuristics indicating embedded URLs and is flagged by a machine learning classifier as malicious. The document body, though heavily obfuscated, suggests a lure related to 'piano sheet music free'. The presence of multiple external URLs, including one that appears to be a PDF file hosted on a suspicious domain, indicates a phishing or malware distribution attempt. The ClamAV detection further confirms its malicious nature, likely as a phishing lure leading to further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/123?utm_term=cerf+volant+piano+sheet+music+free
    • http://taher-tcac.com/diriromozurogatipedajudf7mow.pdf
    • https://static.s123-cdn-static.com/uploads/4451971/normal_5fdfff10b9729.pdf
    • https://cdn-cms.f-static.net/uploads/4409239/normal_601f11584df6c.pdf
    • https://lanuwoga.weebly.com/uploads/1/3/1/6/131637333/zopavujotawifolopoxa.pdf
    • https://suxekupawuva.weebly.com/uploads/1/3/2/7/132710704/radufo.pdf
    • http://talajudoxuxip.mygamesonline.org/genewapabefodagozeralif.pdf
    • http://herss.space/avengers_infinity_war_watch_online_123moviesfxb1s.pdf
    • http://kixiwogazu.sportsontheweb.net/commonlit_assessment_answers.pdf
    • https://cdn-cms.f-static.net/uploads/4489732/normal_5fd3851b9256a.pdf
    • https://cdn-cms.f-static.net/uploads/4476429/normal_602770f2c7964.pdf
    • http://zatoxuvisovapuf.sportsontheweb.net/neoliberalismo_mexicano.pdf
    • https://jogijomovap.weebly.com/uploads/1/3/0/9/130969693/c5fd9.pdf
    • http://vigastlens.xyz/376005344437r7yz.pdf
    • https://cdn-cms.f-static.net/uploads/4366005/normal_6042c565576a4.pdf
    • http://pay-order.info/airplane_pilot_simulator_3d_mod_apkis33g.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://wulibazosuxib.onlinewebshop.net/skewed_t_distribution.pdf
    • http://faleferesevo.onlinewebshop.net/maboduwaperesoxix.pdf
    • https://s3.amazonaws.com/zozofufulolig/74777715882.pdf
    • https://s3.amazonaws.com/gavapozalilup/one_big_party_icivics_answer.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dda1.bin
b7856a44076dd20624214944df2db3a7a1d40645eaf2908dcc3998b2ff027889
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDA1 5220 bytes
font_01_sfnt_off0000ef3b.bin
572d764a48c7de5584eb8292ae22bd7ef1d32c1b2b488498de8b90d2af8ec582
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF3B 11840 bytes