Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c8e0048a0252c40…

MALICIOUS

PDF

81.7 KB Created: 2021-03-01 09:41:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-29
MD5: a4fd0845786cad85027b1eb4357846c0 SHA-1: f4bfdf0bf2b89fcbbdffb414468de81834d7702a SHA-256: 2c8e0048a0252c400fa8f809c0eda277eb0c0f2f3518bb515ac88962c8c79e6b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest an attempt to exploit user interaction via a malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/aws?utm_term=how+to+make+my+crosley+record+player+sound+better PDF link annotation
    • http://sawemawe.mywebcommunity.org/52527044903.pdfIn PDF document text
    • http://fazejajogavu.medianewsonline.com/99986608431.pdfIn PDF document text
    • https://cdn.sqhk.co/zivuwimavez/gjjdX9o/fizeropawujuf.pdfIn PDF document text
    • http://fajujefa.getenjoyment.net/19757247992.pdfIn PDF document text
    • https://cdn.sqhk.co/rubovadu/jajdgfk/vigowawogozepug.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4371790/normal_5ff769e3630b7.pdfIn PDF document text
    • https://cdn.sqhk.co/vipikunowi/hjemLig/pixitracker_1bit_demo.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://vexabimumemig.atwebpages.com/ghost_boy_lyrics_jacob_tillberg.pdfIn PDF document text
    • https://s3.amazonaws.com/magapeguwabe/resumen_del_genesis_biblia_catolica.pdfIn PDF document text
    • https://s3.amazonaws.com/rijaliwiguvex/photoshop_blending_modes_tutorial.pdfIn PDF document text
    • https://s3.amazonaws.com/mexavofezoxi/ardamax_keylogger_for_android_mobile.pdfIn PDF document text
    • https://s3.amazonaws.com/bejenosugede/arthrocare_quantum_2_manual.pdfIn PDF document text
    • https://s3.amazonaws.com/xuxifuzituwu/89553804577.pdfIn PDF document text
    • https://s3.amazonaws.com/wunojipu/34623443115.pdfIn PDF document text
    • https://s3.amazonaws.com/pevarijidasalop/virtual_piano_sheet_music_baby_shark.pdfIn PDF document text
    • https://s3.amazonaws.com/xukirizugukugi/bahubali_2_movie_720p_worldfree4u.pdfIn PDF document text
    • http://letulirabe.epizy.com/96987160368.pdfIn PDF document text
    • http://xobiluwova.epizy.com/56881242565.pdfIn PDF document text
    • http://fupizasatekuw.rf.gd/dodasugajuxibuvi.pdfIn PDF document text
    • https://s3.amazonaws.com/sivanira/buried_alive_2007_full_movie_free.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f4e9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF4E9 5412 bytes
SHA-256: c64df45d4e647209587680f92bffbc6fb6312d496115e38ab71c044043a54c38
font_01_sfnt_off00010740.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10740 10460 bytes
SHA-256: dd48e71d2f9ed6aade8fb0c9fdd7c610831fd6a39cf8653255caa4a155aa107b
font_02_sfnt_off00012b14.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12B14 4324 bytes
SHA-256: 0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333