Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b049ecb1dc006d7…

MALICIOUS

PDF

70.4 KB Created: 2021-04-19 19:21:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b1dcddc040c47e5ccbc5ab62d44cfbfd SHA-1: 79ce79f2800ecc4b5a9e2fad26983ee99ea67a2a SHA-256: 2b049ecb1dc006d7b31d9d507bbb8d25438d4cc25145cafdd6d42ae5bf6ad482
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs suggests an attempt to redirect the user to external sites, potentially for phishing or to download further payloads. The document body, though heavily obfuscated, contains metadata related to wkhtmltopdf, suggesting it might be a generated document used as a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.pharoxglobal.com/sites/default/files/webform/50635107556.pdf
    • https://www.dgs-interparts.be/sites/default/files/64751185730.pdf
    • https://www.visitsavannah.com/sites/default/files/webform/71260674720.pdf
    • http://www.pacificsportfraservalley.com/sites/default/files/webform/joxelivoresilawefuxeli.pdf
    • https://www.a1touchsolution.nl/sites/default/files/larigujumikanezazezogiwi.pdf
    • http://russian-ice-spb.ru/sites/default/files/webform/files/77599308563.pdf
    • http://portal-mysigma.com/system/files/student-proof/41429692510.pdf
    • https://www.ofalloncasting.com/sites/default/files/webform/nunemoxajusadokuxilebe.pdf
    • https://www.mainephilanthropy.org/sites/default/files/5296457674.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/skout/mBVl/~3/3CAf4wW3hvY/uplcv?utm_term=dream+interpretation+cleaning+spider+webs
    • https://community.princeton.edu/system/files/webform/jidubiziro.pdf
    • https://www.vub.be/sites/vub/files/webform/16824703900.pdf
    • https://gradfutures.princeton.edu/system/files/webform/25860956451.pdf
    • https://drones.princeton.edu/system/files/webform/61493424170.pdf
    • https://printandmail.princeton.edu/system/files/webform/85064040694.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d832.bin
f1000d78a643c6055d58e9d5492c4101119da0dc22d8cc5da1ecc7d33809e233
pdf-font-stream PDF embedded font (sfnt) at offset 0xD832 5624 bytes
font_01_sfnt_off0000eb47.bin
db388b26e1495f9c86b98d3c64682dcf84cfd5e2dbe8304181ac892fccd410be
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB47 9824 bytes