Malicious PDF — malware analysis report

Static analysis result for SHA-256 2dcefff96f10384a…

MALICIOUS

PDF

115.6 KB Created: 2020-11-13 08:33:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d9c90d68cad73fb63290a74497a46206 SHA-1: e7d9bb484f8e7e6a95f2a55e9c2e7a2cbab879e5 SHA-256: 2dcefff96f10384a70d8c8258d5e45f78aad4103beb929ac825e1f7b06ed94a5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing an embedded URL that directs users to a suspicious domain. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/aws?utm_term=auditoria+de+sistemas+de+informa%25C3%25A7%25C3%25A3o+pdf
    • https://cdn-cms.f-static.net/uploads/4365551/normal_5f9036595a06c.pdf
    • https://cdn-cms.f-static.net/uploads/4465270/normal_5fad639dcc3e9.pdf
    • https://cdn-cms.f-static.net/uploads/4451760/normal_5fa039a70e4ce.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/juvuraguvutoxif/wesositakelabid.pdf
    • https://s3.amazonaws.com/voxulija/lunafa.pdf
    • https://s3.amazonaws.com/tajimipojimo/mario_kart_ds_action_replay_cheats.pdf
    • https://s3.amazonaws.com/gorajikunobixi/quickbooks_credit_memo_list.pdf
    • https://s3.amazonaws.com/virumutipalis/notajeralepenetifotal.pdf
    • https://s3.amazonaws.com/befarekogol/tikasetusipa.pdf
    • https://s3.amazonaws.com/mamukawaxatali/79479505573.pdf
    • https://s3.amazonaws.com/subud/guxukevewet.pdf
    • https://s3.amazonaws.com/mejados/miwuduvaxagededowipi.pdf
    • https://s3.amazonaws.com/nafoxuda/fda_inspection_manual_for_drugs.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000174f9.bin
7e267230db599da9f107c1b07fc6131a1debf5d77288222846e3383899e6fbb5
pdf-font-stream PDF embedded font (sfnt) at offset 0x174F9 5528 bytes
font_01_sfnt_off0001870d.bin
5b6da55dbfe6e278ac32dc7b3bb597404eb23d1c9c020850ad261e7cb70a9263
pdf-font-stream PDF embedded font (sfnt) at offset 0x1870D 14316 bytes
font_02_sfnt_off0001b0c7.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B0C7 4324 bytes