Malicious PDF — malware analysis report

Static analysis result for SHA-256 2cf55c2d486782e0…

MALICIOUS

PDF

76.3 KB Created: 2021-03-11 16:04:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 4f649dc910cb0c56d7b0d4b205b01848 SHA-1: dcdd5e0c4e6c289a6db6a0bc35047b8462664e12 SHA-256: 2cf55c2d486782e00b78f965c43f2024e2235ac68dadb8e9a632d30b3a55fcd3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, contains text related to search queries, reinforcing the phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=super+smash+bros+brawl+font PDF link annotation
    • https://cdn.sqhk.co/mogezunir/ibQmAhi/78316806461.pdfIn PDF document text
    • http://wide-mean.top/91486385531qh6qd.pdfIn PDF document text
    • https://cdn.sqhk.co/kiribikiv/hjvhijg/elements_of_a_story_plot.pdfIn PDF document text
    • http://passive-income.ru/59933101111lf7gy.pdfIn PDF document text
    • https://cdn.sqhk.co/gisepavuv/D3Vtbji/21852423301.pdfIn PDF document text
    • http://madamzero.com/el_neoliberalismo_en_mexico_unamzugax.pdfIn PDF document text
    • http://zusetuwegu.22web.org/92195073967.pdfIn PDF document text
    • http://kifenefazujiz.iblogger.org/69750252295.pdfIn PDF document text
    • http://fofitev.22web.org/youtube_horoscopo_semanal_por_profesor_zellagro.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/legobegutulo/2068666675.pdfIn PDF document text
    • https://s3.amazonaws.com/wufujudisu/98148213710.pdfIn PDF document text
    • https://s3.amazonaws.com/degisapemifa/57612994409.pdfIn PDF document text
    • https://s3.amazonaws.com/daraniwekamidir/beaconmedaes_design_guide.pdfIn PDF document text
    • https://s3.amazonaws.com/zuguvoxoki/10333637431.pdfIn PDF document text
    • https://s3.amazonaws.com/zaxawetawupo/chesapeake_shores_episode_guide_wiki.pdfIn PDF document text
    • https://s3.amazonaws.com/seriposuj/uppercase_letter_d_template.pdfIn PDF document text
    • https://s3.amazonaws.com/lowuwofuxali/13717174975.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ca51.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCA51 5312 bytes
SHA-256: 60e799b3e2718d704a7b37188e39f8eff9da8e579b11a5df54c25c9d9158ef0b
font_01_sfnt_off0000dc44.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC44 10656 bytes
SHA-256: e34b5fd992ede8d88b880d3a34767e42ccadd7601c454a85fcfb2467e0366ffc
font_02_sfnt_off000100ff.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x100FF 16084 bytes
SHA-256: fb27248ec02d804caa0ce6a8dd06a8f0f211157336bc50f6c382585ff5fe3da3
font_03_sfnt_off000115b6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x115B6 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3